{"grype_matches":[{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2687","versionConstraint":"<1.21.9||>=1.22.0-0,<1.22.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2687","fix":{"state":"fixed","versions":["1.21.9","1.22.2"],"available":[{"date":"2024-04-03","kind":"release","version":"1.21.9"},{"date":"2024-04-03","kind":"release","version":"1.22.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45288","date":"2026-10-08","epss":0.91969,"percentile":0.99819}],"risk":68.97675,"urls":["https://go.dev/cl/576155","https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/65051","description":"An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.\n\nMaintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed.\n\nThis permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send.\n\nThe fix sets a limit on the amount of excess header frames we will process before closing a connection."},"relatedVulnerabilities":[{"id":"CVE-2023-45288","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45288","date":"2026-10-08","epss":0.91969,"percentile":0.99819}],"urls":["http://www.openwall.com/lists/oss-security/2024/04/03/16","http://www.openwall.com/lists/oss-security/2024/04/05/4","https://go.dev/cl/576155","https://go.dev/issue/65051","https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRYFHIQ6XRKRYBI2F5UESH67BJBQXUPT/","https://pkg.go.dev/vuln/GO-2024-2687","https://security.netapp.com/advisory/ntap-20240419-0009/","https://www.kb.cert.org/vuls/id/421644"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45288","description":"An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection."},{"id":"GHSA-4v7x-pqxf-cx7m","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45288","date":"2026-10-08","epss":0.91969,"percentile":0.99819}],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-45288","https://go.dev/cl/576155","https://go.dev/issue/65051","https://groups.google.com/g/golang-announce/c/YgW0sx8mN3M","https://pkg.go.dev/vuln/GO-2024-2687","https://nowotarski.info/http2-continuation-flood-technical-details","https://security.netapp.com/advisory/ntap-20240419-0009","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QRYFHIQ6XRKRYBI2F5UESH67BJBQXUPT","http://www.openwall.com/lists/oss-security/2024/04/03/16","http://www.openwall.com/lists/oss-security/2024/04/05/4","https://www.kb.cert.org/vuls/id/421644"],"severity":"Medium","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-4v7x-pqxf-cx7m","description":"net/http, x/net/http2: close connections when receiving too many headers"}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0433","versionConstraint":"<1.17.9||>=1.18.0-0,<1.18.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0433","fix":{"state":"fixed","versions":["1.17.9","1.18.1"],"available":[{"date":"2022-04-12","kind":"release","version":"1.17.9"},{"date":"2022-04-12","kind":"release","version":"1.18.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24675","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24675","date":"2026-10-08","epss":0.0995,"percentile":0.95486}],"risk":7.4624999999999995,"urls":["https://go.googlesource.com/go/+/45c3387d777caf28f4b992ad9a6216e3085bb8fe","https://go.dev/issue/51853","https://groups.google.com/g/golang-announce/c/oecdBNLOml8"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/399820","description":"encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data."},"relatedVulnerabilities":[{"id":"CVE-2022-24675","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24675","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24675","date":"2026-10-08","epss":0.0995,"percentile":0.95486}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf","https://groups.google.com/g/golang-announce","https://groups.google.com/g/golang-announce/c/oecdBNLOml8","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/","https://security.gentoo.org/glsa/202208-02","https://security.netapp.com/advisory/ntap-20220915-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24675","description":"encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1571","versionConstraint":"<1.19.6||>=1.20.0-0,<1.20.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1571","fix":{"state":"fixed","versions":["1.19.6","1.20.1"],"available":[{"date":"2023-02-14","kind":"release","version":"1.19.6"},{"date":"2023-02-14","kind":"release","version":"1.20.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41723","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41723","date":"2026-10-08","epss":0.04561,"percentile":0.91357}],"risk":3.42075,"urls":["https://go.dev/cl/468135","https://go.dev/cl/468295","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/57855","description":"A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests."},"relatedVulnerabilities":[{"id":"CVE-2022-41723","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41723","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41723","date":"2026-10-08","epss":0.04561,"percentile":0.91357}],"urls":["https://go.dev/cl/468135","https://go.dev/cl/468295","https://go.dev/issue/57855","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MA5XS5DAOJ5PKKNG5TUXKPQOFHT5VBC/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGW7GE2Z32ZT47UFAQFDRQE33B7Q7LMT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/","https://pkg.go.dev/vuln/GO-2023-1571","https://security.gentoo.org/glsa/202311-09","https://www.couchbase.com/alerts/","https://security.netapp.com/advisory/ntap-20230331-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41723","description":"A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests."},{"id":"GHSA-vvpx-j8f3-3w6h","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41723","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41723","date":"2026-10-08","epss":0.04561,"percentile":0.91357}],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-41723","https://go.dev/cl/468135","https://go.dev/issue/57855","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E","https://vuln.go.dev/ID/GO-2023-1571.json","https://go.dev/cl/468295","https://pkg.go.dev/vuln/GO-2023-1571","https://security.gentoo.org/glsa/202311-09","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MA5XS5DAOJ5PKKNG5TUXKPQOFHT5VBC","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGW7GE2Z32ZT47UFAQFDRQE33B7Q7LMT","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE","https://www.couchbase.com/alerts"],"severity":"High","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-vvpx-j8f3-3w6h","description":"golang.org/x/net vulnerable to Uncontrolled Resource Consumption"}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0435","versionConstraint":"<1.17.9||>=1.18.0-0,<1.18.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0435","fix":{"state":"fixed","versions":["1.17.9","1.18.1"],"available":[{"date":"2022-04-12","kind":"release","version":"1.17.9"},{"date":"2022-04-12","kind":"release","version":"1.18.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-28327","date":"2026-10-08","epss":0.04195,"percentile":0.90687}],"risk":3.14625,"urls":["https://go.googlesource.com/go/+/37065847d87df92b5eb246c88ba2085efcf0b331","https://go.dev/issue/52075","https://groups.google.com/g/golang-announce/c/oecdBNLOml8"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/397135","description":"A crafted scalar input longer than 32 bytes can cause P256().ScalarMult or P256().ScalarBaseMult to panic. Indirect uses through crypto/ecdsa and crypto/tls are unaffected. amd64, arm64, ppc64le, and s390x are unaffected."},"relatedVulnerabilities":[{"id":"CVE-2022-28327","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-28327","date":"2026-10-08","epss":0.04195,"percentile":0.90687}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-744259.pdf","https://groups.google.com/g/golang-announce","https://groups.google.com/g/golang-announce/c/oecdBNLOml8","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TYZC4OAY54TO75FBEFAPV5G7O4D5TM/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F3BMW5QGX53CMIJIZWKXFKBJX2C5GWTY/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NY6GEAJMNKKMU5H46QO4D7D6A24KSPXE/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RCRSABD6CUDIZULZPZL5BJ3ET3A2NEJP/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/","https://security.gentoo.org/glsa/202208-02","https://security.netapp.com/advisory/ntap-20220915-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-28327","description":"The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-1144","versionConstraint":"<1.18.9||>=1.19.0-0,<1.19.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-1144","fix":{"state":"fixed","versions":["1.18.9","1.19.4"],"available":[{"date":"2022-12-06","kind":"release","version":"1.18.9"},{"date":"2022-12-06","kind":"release","version":"1.19.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41717","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41717","date":"2026-10-08","epss":0.06077,"percentile":0.93221}],"risk":3.129655,"urls":["https://go.dev/cl/455717","https://go.dev/cl/455635","https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/56350","description":"An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests.\n\nHTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection."},"relatedVulnerabilities":[{"id":"CVE-2022-41717","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41717","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41717","date":"2026-10-08","epss":0.06077,"percentile":0.93221}],"urls":["https://go.dev/cl/455635","https://go.dev/cl/455717","https://go.dev/issue/56350","https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4SBIUECMLNC572P23DDOKJNKPJVX26SP/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/56B2FFESRYYP6IY2AZ3UWXLWKZ5IYZN4/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANIOPUXWIHVRA6CEWXCGOMX3YYS6KFHG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSVIS6MTMFVBA7JPMRAUNKUOYEVSJYSB/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NQGNAXK3YBPMUP3J4TECIRDHFGW37522/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PUM4DIVOLJCBK5ZDP4LJOL24GXT3YSIR/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PW3XC47AUW5J5M2ULJX7WCCL3B2ETLMT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q52IQI754YAE4XPR4QBRWPIVZWYGZ4FS/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QBKBAZBIOXZV5QCFHZNSVXULR32XJCYD/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WPEIZ7AMEJCZXU3FEJZMVRNHQZXX5P3I/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV/","https://pkg.go.dev/vuln/GO-2022-1144","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20230120-0008/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41717","description":"An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection."},{"id":"GHSA-xrjj-mj9h-534m","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41717","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41717","date":"2026-10-08","epss":0.06077,"percentile":0.93221}],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-41717","https://go.dev/cl/455635","https://go.dev/cl/455717","https://go.dev/issue/56350","https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ","https://pkg.go.dev/vuln/GO-2022-1144","https://security.gentoo.org/glsa/202311-09","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WPEIZ7AMEJCZXU3FEJZMVRNHQZXX5P3I","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QBKBAZBIOXZV5QCFHZNSVXULR32XJCYD","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q52IQI754YAE4XPR4QBRWPIVZWYGZ4FS","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PW3XC47AUW5J5M2ULJX7WCCL3B2ETLMT","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PUM4DIVOLJCBK5ZDP4LJOL24GXT3YSIR","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NQGNAXK3YBPMUP3J4TECIRDHFGW37522","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSVIS6MTMFVBA7JPMRAUNKUOYEVSJYSB","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ANIOPUXWIHVRA6CEWXCGOMX3YYS6KFHG","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/56B2FFESRYYP6IY2AZ3UWXLWKZ5IYZN4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4SBIUECMLNC572P23DDOKJNKPJVX26SP","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2"],"severity":"Medium","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-xrjj-mj9h-534m","description":"golang.org/x/net/http2 vulnerable to possible excessive memory growth"}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.20.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-2102","versionConstraint":"<1.20.10||>=1.21.0-0,<1.21.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-2102","fix":{"state":"fixed","versions":["1.20.10","1.21.3"],"available":[{"date":"2023-10-10","kind":"release","version":"1.20.10"},{"date":"2023-10-10","kind":"release","version":"1.21.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39325","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39325","date":"2026-10-08","epss":0.03796,"percentile":0.89716}],"risk":2.8470000000000004,"urls":["https://go.dev/cl/534215","https://go.dev/cl/534235","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/63417","description":"A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing.\n\nWith the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection.\n\nThis issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2.\n\nThe default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function."},"relatedVulnerabilities":[{"id":"CVE-2023-39325","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39325","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39325","date":"2026-10-08","epss":0.03796,"percentile":0.89716}],"urls":["https://go.dev/cl/534215","https://go.dev/cl/534235","https://go.dev/issue/63417","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OVW5V2DM5K5IC3H7O42YDUGNJ74J35O/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SZN67IL7HMGMNAVLOTIXLIHUDXZK4LH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WJ4QVX2AMUJ2F2S27POOAHRC4K3CHU4/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVZDNSMVDAQJ64LJC5I5U5LDM5753647/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2BBIDR2ZMB3X5BC7SR4SLQMHRMVPY6L/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRC75BQJP6FJN2L7KCKYZW4DSBD7QSD/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FTMJ3NJIDAZFWJQQSP3L22MUFJ3UP2PT/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSY7SXFFTPZFWDM6XELSDSHZLVW3AHK7/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZQIELEIRSZUYTFFH5KTH2YJ4IIQG2KE/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPWCNYB5PQ5PCVZ4NJT6G56ZYFZ5QBU6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5E5JSJBZLYXOTZWXHJKRVCIXIHVWKJ6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZQYOOKHQDQ57LV2IAG6NRFOVXKHJJ3Z/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NG7IMPL55MVWU3LCI4JQJT3K2U5CHDV7/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ODBY7RVMGZCBSTWF2OZGIZS57FNFUL67/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXGWPQOJ3JNDW2XIYKIVJ7N7QUIFNM2Q/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PJCUNGIQDUMZ4Z6HWVYIMR66A35F5S74/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QF5QSYAOPDOWLY6DUHID56Q4HQFYB45I/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXOU2JZUBEBP7GBKAYIJRPRBZSJCD7ST/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3UETKPUB3V5JS5TLZOF3SMTGT5K5APS/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULQQONMSCQSH5Z5OWFFQHCGEZ3NL4DRJ/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTT7DG3QOF5ZNJLUGHDNLRUIN6OWZARP/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2LZSWTV4NV4SNQARNXG5T6LRHP26EW2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCNCBYKZXLDFGAJUB7ZP5VLC3YTHJNVH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XTNLSL44Y5FB6JWADSZH6DCV4JJAAEQY/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJWHBLVZDM5KQSDFRBFRKU5KSSOLIRQ4/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRKEXKANQ7BKJW2YTAMP625LJUJZLJ4P/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV/","https://pkg.go.dev/vuln/GO-2023-2102","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20231110-0008/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39325","description":"A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function."},{"id":"GHSA-4374-p667-p6c8","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39325","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39325","date":"2026-10-08","epss":0.03796,"percentile":0.89716}],"urls":["https://github.com/golang/go/issues/63417","https://go.dev/cl/534215","https://go.dev/cl/534235","https://go.dev/issue/63417","https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo/m/UDd7VKQuAAAJ","https://nvd.nist.gov/vuln/detail/CVE-2023-39325","https://pkg.go.dev/vuln/GO-2023-2102","https://security.gentoo.org/glsa/202311-09","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3OVW5V2DM5K5IC3H7O42YDUGNJ74J35O","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3SZN67IL7HMGMNAVLOTIXLIHUDXZK4LH","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4BUK2ZIAGCULOOYDNH25JPU6JBES5NF2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5RSKA2II6QTD4YUKUNDVJQSRYSFC4VFR","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AVZDNSMVDAQJ64LJC5I5U5LDM5753647","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D2BBIDR2ZMB3X5BC7SR4SLQMHRMVPY6L","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRC75BQJP6FJN2L7KCKYZW4DSBD7QSD","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FTMJ3NJIDAZFWJQQSP3L22MUFJ3UP2PT","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSY7SXFFTPZFWDM6XELSDSHZLVW3AHK7","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZQIELEIRSZUYTFFH5KTH2YJ4IIQG2KE","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPWCNYB5PQ5PCVZ4NJT6G56ZYFZ5QBU6","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MZQYOOKHQDQ57LV2IAG6NRFOVXKHJJ3Z","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NG7IMPL55MVWU3LCI4JQJT3K2U5CHDV7","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXGWPQOJ3JNDW2XIYKIVJ7N7QUIFNM2Q","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PJCUNGIQDUMZ4Z6HWVYIMR66A35F5S74","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QF5QSYAOPDOWLY6DUHID56Q4HQFYB45I","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3UETKPUB3V5JS5TLZOF3SMTGT5K5APS","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/REMHVVIBDNKSRKNOTV7EQSB7CYQWOUOU","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7N5GV4CHH6WAGX3GFMDD3COEOVCZ4RI","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULQQONMSCQSH5Z5OWFFQHCGEZ3NL4DRJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTT7DG3QOF5ZNJLUGHDNLRUIN6OWZARP","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W2LZSWTV4NV4SNQARNXG5T6LRHP26EW2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WCNCBYKZXLDFGAJUB7ZP5VLC3YTHJNVH","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XTNLSL44Y5FB6JWADSZH6DCV4JJAAEQY","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YRKEXKANQ7BKJW2YTAMP625LJUJZLJ4P","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZSVEMQV5ROY5YW5QE3I57HT3ITWG5GCV","https://security.netapp.com/advisory/ntap-20231110-0008","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5E5JSJBZLYXOTZWXHJKRVCIXIHVWKJ6","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YJWHBLVZDM5KQSDFRBFRKU5KSSOLIRQ4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ODBY7RVMGZCBSTWF2OZGIZS57FNFUL67","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QXOU2JZUBEBP7GBKAYIJRPRBZSJCD7ST","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WJ4QVX2AMUJ2F2S27POOAHRC4K3CHU4"],"severity":"High","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-4374-p667-p6c8","description":"HTTP/2 rapid reset can cause excessive work in net/http"}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0969","versionConstraint":"<1.18.6||>=1.19.0-0,<1.19.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0969","fix":{"state":"fixed","versions":["1.18.6","1.19.1"],"available":[{"date":"2022-09-06","kind":"release","version":"1.18.6"},{"date":"2022-09-06","kind":"release","version":"1.19.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27664","date":"2026-10-08","epss":0.03269,"percentile":0.88055}],"risk":2.4517499999999997,"urls":["https://go.dev/issue/54658","https://go.dev/cl/428735"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/x49AQzIVX-s","description":"HTTP/2 server connections can hang forever waiting for a clean shutdown that was preempted by a fatal error. This condition can be exploited by a malicious client to cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27664","date":"2026-10-08","epss":0.03269,"percentile":0.88055}],"urls":["https://groups.google.com/g/golang-announce","https://groups.google.com/g/golang-announce/c/x49AQzIVX-s","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX/","https://security.gentoo.org/glsa/202209-26","https://security.netapp.com/advisory/ntap-20220923-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27664","description":"In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error."},{"id":"GHSA-69cg-p879-7622","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-27664","date":"2026-10-08","epss":0.03269,"percentile":0.88055}],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-27664","https://groups.google.com/g/golang-announce","https://groups.google.com/g/golang-announce/c/x49AQzIVX-s","https://security.gentoo.org/glsa/202209-26","https://pkg.go.dev/vuln/GO-2022-0969","https://go.dev/cl/428735","https://go.dev/issue/54658","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXS2OQ57KZC5XZKK5UW4SYKPVQAHIOJX","https://security.netapp.com/advisory/ntap-20220923-0004"],"severity":"High","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-69cg-p879-7622","description":"golang.org/x/net/http2 Denial of Service vulnerability"}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-55298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55298","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"risk":2.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55298"},"relatedVulnerabilities":[{"id":"CVE-2025-55298","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9ccg-6pjw-x645","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55298","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from heap overflow to remote code execution. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55298","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"risk":2.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55298"},"relatedVulnerabilities":[{"id":"CVE-2025-55298","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9ccg-6pjw-x645","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55298","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from heap overflow to remote code execution. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55298","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"risk":2.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55298"},"relatedVulnerabilities":[{"id":"CVE-2025-55298","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9ccg-6pjw-x645","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55298","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from heap overflow to remote code execution. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55298","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"risk":2.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55298"},"relatedVulnerabilities":[{"id":"CVE-2025-55298","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9ccg-6pjw-x645","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55298","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from heap overflow to remote code execution. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55298","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55298","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"risk":2.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55298"},"relatedVulnerabilities":[{"id":"CVE-2025-55298","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55298","cwe":"CWE-123","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-55298","cwe":"CWE-134","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55298","date":"2026-10-08","epss":0.0449,"percentile":0.91239}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9ccg-6pjw-x645","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55298","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from heap overflow to remote code execution. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1703","versionConstraint":"<1.19.8||>=1.20.0-0,<1.20.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1703","fix":{"state":"fixed","versions":["1.19.8","1.20.3"],"available":[{"date":"2023-04-04","kind":"release","version":"1.19.8"},{"date":"2023-04-04","kind":"release","version":"1.20.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24538","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24538","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24538","date":"2026-10-08","epss":0.02281,"percentile":0.82616}],"risk":2.14414,"urls":["https://go.dev/cl/482079","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/59234","description":"Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected.\n\nBackticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template.\n\nAs ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. \"var a = {{.}}\"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml.\n\nWith fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21.\n\nUsers who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution."},"relatedVulnerabilities":[{"id":"CVE-2023-24538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24538","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24538","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24538","date":"2026-10-08","epss":0.02281,"percentile":0.82616}],"urls":["https://go.dev/cl/482079","https://go.dev/issue/59234","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8","https://pkg.go.dev/vuln/GO-2023-1703","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20241115-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24538","description":"Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary Javascript code into the Go template. As ES6 template literals are rather complex, and themselves can do string interpolation, the decision was made to simply disallow Go template actions from being used inside of them (e.g. \"var a = {{.}}\"), since there is no obviously safe way to allow this behavior. This takes the same approach as github.com/google/safehtml. With fix, Template.Parse returns an Error when it encounters templates like this, with an ErrorCode of value 12. This ErrorCode is currently unexported, but will be exported in the release of Go 1.21. Users who rely on the previous behavior can re-enable it using the GODEBUG flag jstmpllitinterp=1, with the caveat that backticks will now be escaped. This should be used with caution."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.20.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-2185","versionConstraint":"<1.20.11||>=1.21.0-0,<1.21.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-2185","fix":{"state":"fixed","versions":["1.20.11","1.21.4"],"available":[{"date":"2023-11-07","kind":"release","version":"1.20.11"},{"date":"2023-11-07","kind":"release","version":"1.21.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45283","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45283","date":"2026-10-08","epss":0.02758,"percentile":0.85831}],"risk":2.0685000000000002,"urls":["https://go.dev/cl/540277","https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY","https://go.dev/issue/64028","https://go.dev/cl/541175","https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/63713","description":"The filepath package does not recognize paths with a \\??\\ prefix as special.\n\nOn Windows, a path beginning with \\??\\ is a Root Local Device path equivalent to a path beginning with \\\\?\\. Paths with a \\??\\ prefix may be used to access arbitrary locations on the system. For example, the path \\??\\c:\\x is equivalent to the more common path c:\\x.\n\nBefore fix, Clean could convert a rooted path such as \\a\\..\\??\\b into the root local device path \\??\\b. Clean will now convert this to .\\??\\b.\n\nSimilarly, Join(\\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \\??\\b. Join will now convert this to \\.\\??\\b.\n\nIn addition, with fix, IsAbs now correctly reports paths beginning with \\??\\ as absolute, and VolumeName correctly reports the \\??\\ prefix as a volume name.\n\nUPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \\?, resulting in filepath.Clean(\\?\\c:) returning \\?\\c: rather than \\?\\c:\\ (among other effects). The previous behavior has been restored."},"relatedVulnerabilities":[{"id":"CVE-2023-45283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45283","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45283","date":"2026-10-08","epss":0.02758,"percentile":0.85831}],"urls":["http://www.openwall.com/lists/oss-security/2023/12/05/2","https://go.dev/cl/540277","https://go.dev/cl/541175","https://go.dev/issue/63713","https://go.dev/issue/64028","https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY","https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ","https://pkg.go.dev/vuln/GO-2023-2185","https://security.netapp.com/advisory/ntap-20231214-0008/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45283","description":"The filepath package does not recognize paths with a \\??\\ prefix as special. On Windows, a path beginning with \\??\\ is a Root Local Device path equivalent to a path beginning with \\\\?\\. Paths with a \\??\\ prefix may be used to access arbitrary locations on the system. For example, the path \\??\\c:\\x is equivalent to the more common path c:\\x. Before fix, Clean could convert a rooted path such as \\a\\..\\??\\b into the root local device path \\??\\b. Clean will now convert this to .\\??\\b. Similarly, Join(\\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \\??\\b. Join will now convert this to \\.\\??\\b. In addition, with fix, IsAbs now correctly reports paths beginning with \\??\\ as absolute, and VolumeName correctly reports the \\??\\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \\?, resulting in filepath.Clean(\\?\\c:) returning \\?\\c: rather than \\?\\c:\\ (among other effects). The previous behavior has been restored."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0537","versionConstraint":"<1.17.13||>=1.18.0-0,<1.18.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0537","fix":{"state":"fixed","versions":["1.17.13","1.18.5"],"available":[{"date":"2022-08-01","kind":"release","version":"1.17.13"},{"date":"2022-08-01","kind":"release","version":"1.18.5"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-32189","date":"2026-10-08","epss":0.02629,"percentile":0.85058}],"risk":1.97175,"urls":["https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66","https://go.dev/issue/53871","https://groups.google.com/g/golang-announce/c/YqYYG87xB10"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417774","description":"Decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-32189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-32189","date":"2026-10-08","epss":0.02629,"percentile":0.85058}],"urls":["https://go.dev/cl/417774","https://go.dev/issue/53871","https://go.googlesource.com/go/+/055113ef364337607e3e72ed7d48df67fde6fc66","https://groups.google.com/g/golang-announce/c/YqYYG87xB10","https://pkg.go.dev/vuln/GO-2022-0537"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32189","description":"A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2887","versionConstraint":"<1.21.11||>=1.22.0-0,<1.22.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2887","fix":{"state":"fixed","versions":["1.21.11","1.22.4"],"available":[{"date":"2024-06-04","kind":"release","version":"1.21.11"},{"date":"2024-06-04","kind":"release","version":"1.22.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24790","date":"2026-10-08","epss":0.01952,"percentile":0.79639}],"risk":1.8348800000000003,"urls":["https://go.dev/issue/67680","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/590316","description":"The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms."},"relatedVulnerabilities":[{"id":"CVE-2024-24790","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24790","date":"2026-10-08","epss":0.01952,"percentile":0.79639}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/04/1","https://go.dev/cl/590316","https://go.dev/issue/67680","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ","https://pkg.go.dev/vuln/GO-2024-2887","https://security.netapp.com/advisory/ntap-20240905-0002/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24790","description":"The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0521","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0521","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-28131","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-28131","date":"2026-10-08","epss":0.02418,"percentile":0.83666}],"risk":1.8135,"urls":["https://go.googlesource.com/go/+/08c46ed43d80bbb67cb904944ea3417989be4af3","https://go.dev/issue/53614","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417062","description":"Calling Decoder.Skip when parsing a deeply nested XML document can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2022-28131","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-28131","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-28131","date":"2026-10-08","epss":0.02418,"percentile":0.83666}],"urls":["https://go.dev/cl/417062","https://go.dev/issue/53614","https://go.googlesource.com/go/+/08c46ed43d80bbb67cb904944ea3417989be4af3","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0521"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-28131","description":"Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4341","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4341","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"risk":1.7445,"urls":["https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736712","description":"The net/url package does not set a limit on the number of query parameters in a query.\n\nWhile the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61726","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"urls":["https://go.dev/cl/736712","https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4341","https://access.redhat.com/errata/RHSA-2026:10096","https://access.redhat.com/errata/RHSA-2026:10104","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:11408","https://access.redhat.com/errata/RHSA-2026:11414","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13542","https://access.redhat.com/errata/RHSA-2026:13548","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:15984","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17446","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17595","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:18913","https://access.redhat.com/errata/RHSA-2026:19013","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26420","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2706","https://access.redhat.com/errata/RHSA-2026:2708","https://access.redhat.com/errata/RHSA-2026:2709","https://access.redhat.com/errata/RHSA-2026:2754","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:2914","https://access.redhat.com/errata/RHSA-2026:2920","https://access.redhat.com/errata/RHSA-2026:3035","https://access.redhat.com/errata/RHSA-2026:3040","https://access.redhat.com/errata/RHSA-2026:3089","https://access.redhat.com/errata/RHSA-2026:3092","https://access.redhat.com/errata/RHSA-2026:3184","https://access.redhat.com/errata/RHSA-2026:3186","https://access.redhat.com/errata/RHSA-2026:3187","https://access.redhat.com/errata/RHSA-2026:3188","https://access.redhat.com/errata/RHSA-2026:3192","https://access.redhat.com/errata/RHSA-2026:3193","https://access.redhat.com/errata/RHSA-2026:3291","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:3297","https://access.redhat.com/errata/RHSA-2026:3298","https://access.redhat.com/errata/RHSA-2026:3336","https://access.redhat.com/errata/RHSA-2026:3337","https://access.redhat.com/errata/RHSA-2026:3340","https://access.redhat.com/errata/RHSA-2026:3341","https://access.redhat.com/errata/RHSA-2026:3343","https://access.redhat.com/errata/RHSA-2026:3391","https://access.redhat.com/errata/RHSA-2026:3416","https://access.redhat.com/errata/RHSA-2026:3427","https://access.redhat.com/errata/RHSA-2026:3459","https://access.redhat.com/errata/RHSA-2026:3468","https://access.redhat.com/errata/RHSA-2026:3469","https://access.redhat.com/errata/RHSA-2026:3470","https://access.redhat.com/errata/RHSA-2026:3471","https://access.redhat.com/errata/RHSA-2026:3472","https://access.redhat.com/errata/RHSA-2026:3473","https://access.redhat.com/errata/RHSA-2026:3489","https://access.redhat.com/errata/RHSA-2026:3506","https://access.redhat.com/errata/RHSA-2026:3556","https://access.redhat.com/errata/RHSA-2026:3559","https://access.redhat.com/errata/RHSA-2026:3668","https://access.redhat.com/errata/RHSA-2026:3669","https://access.redhat.com/errata/RHSA-2026:36873","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/errata/RHSA-2026:3699","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:3752","https://access.redhat.com/errata/RHSA-2026:3753","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3812","https://access.redhat.com/errata/RHSA-2026:3813","https://access.redhat.com/errata/RHSA-2026:3814","https://access.redhat.com/errata/RHSA-2026:3815","https://access.redhat.com/errata/RHSA-2026:3816","https://access.redhat.com/errata/RHSA-2026:3817","https://access.redhat.com/errata/RHSA-2026:3818","https://access.redhat.com/errata/RHSA-2026:3820","https://access.redhat.com/errata/RHSA-2026:3821","https://access.redhat.com/errata/RHSA-2026:3822","https://access.redhat.com/errata/RHSA-2026:3831","https://access.redhat.com/errata/RHSA-2026:3833","https://access.redhat.com/errata/RHSA-2026:3835","https://access.redhat.com/errata/RHSA-2026:3836","https://access.redhat.com/errata/RHSA-2026:3838","https://access.redhat.com/errata/RHSA-2026:3839","https://access.redhat.com/errata/RHSA-2026:3840","https://access.redhat.com/errata/RHSA-2026:3841","https://access.redhat.com/errata/RHSA-2026:3843","https://access.redhat.com/errata/RHSA-2026:3854","https://access.redhat.com/errata/RHSA-2026:3855","https://access.redhat.com/errata/RHSA-2026:3856","https://access.redhat.com/errata/RHSA-2026:3864","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3875","https://access.redhat.com/errata/RHSA-2026:3879","https://access.redhat.com/errata/RHSA-2026:3880","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3898","https://access.redhat.com/errata/RHSA-2026:3905","https://access.redhat.com/errata/RHSA-2026:3906","https://access.redhat.com/errata/RHSA-2026:3928","https://access.redhat.com/errata/RHSA-2026:3929","https://access.redhat.com/errata/RHSA-2026:3930","https://access.redhat.com/errata/RHSA-2026:3931","https://access.redhat.com/errata/RHSA-2026:3932","https://access.redhat.com/errata/RHSA-2026:3958","https://access.redhat.com/errata/RHSA-2026:3959","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:3970","https://access.redhat.com/errata/RHSA-2026:3971","https://access.redhat.com/errata/RHSA-2026:3972","https://access.redhat.com/errata/RHSA-2026:3973","https://access.redhat.com/errata/RHSA-2026:3974","https://access.redhat.com/errata/RHSA-2026:3977","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:3985","https://access.redhat.com/errata/RHSA-2026:40924","https://access.redhat.com/errata/RHSA-2026:4164","https://access.redhat.com/errata/RHSA-2026:4166","https://access.redhat.com/errata/RHSA-2026:4170","https://access.redhat.com/errata/RHSA-2026:4174","https://access.redhat.com/errata/RHSA-2026:4177","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:4211","https://access.redhat.com/errata/RHSA-2026:4220","https://access.redhat.com/errata/RHSA-2026:4256","https://access.redhat.com/errata/RHSA-2026:4264","https://access.redhat.com/errata/RHSA-2026:4267","https://access.redhat.com/errata/RHSA-2026:4270","https://access.redhat.com/errata/RHSA-2026:4276","https://access.redhat.com/errata/RHSA-2026:4434","https://access.redhat.com/errata/RHSA-2026:4435","https://access.redhat.com/errata/RHSA-2026:4460","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:4498","https://access.redhat.com/errata/RHSA-2026:4500","https://access.redhat.com/errata/RHSA-2026:4510","https://access.redhat.com/errata/RHSA-2026:4511","https://access.redhat.com/errata/RHSA-2026:4672","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:4753","https://access.redhat.com/errata/RHSA-2026:4892","https://access.redhat.com/errata/RHSA-2026:4901","https://access.redhat.com/errata/RHSA-2026:4907","https://access.redhat.com/errata/RHSA-2026:4939","https://access.redhat.com/errata/RHSA-2026:4942","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:4952","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5022","https://access.redhat.com/errata/RHSA-2026:5030","https://access.redhat.com/errata/RHSA-2026:5031","https://access.redhat.com/errata/RHSA-2026:5076","https://access.redhat.com/errata/RHSA-2026:5077","https://access.redhat.com/errata/RHSA-2026:5078","https://access.redhat.com/errata/RHSA-2026:5079","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:5129","https://access.redhat.com/errata/RHSA-2026:5130","https://access.redhat.com/errata/RHSA-2026:5131","https://access.redhat.com/errata/RHSA-2026:5132","https://access.redhat.com/errata/RHSA-2026:5145","https://access.redhat.com/errata/RHSA-2026:5146","https://access.redhat.com/errata/RHSA-2026:5168","https://access.redhat.com/errata/RHSA-2026:5327","https://access.redhat.com/errata/RHSA-2026:5394","https://access.redhat.com/errata/RHSA-2026:5439","https://access.redhat.com/errata/RHSA-2026:5444","https://access.redhat.com/errata/RHSA-2026:5447","https://access.redhat.com/errata/RHSA-2026:5452","https://access.redhat.com/errata/RHSA-2026:5461","https://access.redhat.com/errata/RHSA-2026:5463","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5533","https://access.redhat.com/errata/RHSA-2026:5544","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:5636","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:5645","https://access.redhat.com/errata/RHSA-2026:5649","https://access.redhat.com/errata/RHSA-2026:5665","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:5807","https://access.redhat.com/errata/RHSA-2026:5851","https://access.redhat.com/errata/RHSA-2026:5852","https://access.redhat.com/errata/RHSA-2026:5853","https://access.redhat.com/errata/RHSA-2026:5948","https://access.redhat.com/errata/RHSA-2026:5950","https://access.redhat.com/errata/RHSA-2026:5952","https://access.redhat.com/errata/RHSA-2026:5968","https://access.redhat.com/errata/RHSA-2026:6184","https://access.redhat.com/errata/RHSA-2026:6192","https://access.redhat.com/errata/RHSA-2026:6226","https://access.redhat.com/errata/RHSA-2026:6251","https://access.redhat.com/errata/RHSA-2026:6277","https://access.redhat.com/errata/RHSA-2026:6278","https://access.redhat.com/errata/RHSA-2026:6428","https://access.redhat.com/errata/RHSA-2026:6429","https://access.redhat.com/errata/RHSA-2026:6497","https://access.redhat.com/errata/RHSA-2026:6554","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:6567","https://access.redhat.com/errata/RHSA-2026:6568","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:7052","https://access.redhat.com/errata/RHSA-2026:7249","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7676","https://access.redhat.com/errata/RHSA-2026:7854","https://access.redhat.com/errata/RHSA-2026:7942","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8218","https://access.redhat.com/errata/RHSA-2026:8229","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8431","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9848","https://access.redhat.com/security/cve/CVE-2025-61726","https://bugzilla.redhat.com/show_bug.cgi?id=2434432","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61726","description":"The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0533","versionConstraint":"<1.17.11||>=1.18.0-0,<1.18.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0533","fix":{"state":"fixed","versions":["1.17.11","1.18.3"],"available":[{"date":"2022-06-01","kind":"release","version":"1.17.11"},{"date":"2022-06-01","kind":"release","version":"1.18.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29804","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29804","date":"2026-10-08","epss":0.02261,"percentile":0.82453}],"risk":1.69575,"urls":["https://go.googlesource.com/go/+/9cd1818a7d019c02fa4898b3e45a323e35033290","https://go.dev/issue/52476","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/401595","description":"On Windows, the filepath.Clean function can convert certain invalid paths to valid, absolute paths, potentially allowing a directory traversal attack.\n\nFor example, Clean(\".\\c:\") returns \"c:\"."},"relatedVulnerabilities":[{"id":"CVE-2022-29804","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29804","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29804","date":"2026-10-08","epss":0.02261,"percentile":0.82453}],"urls":["https://go.dev/cl/401595","https://go.dev/issue/52476","https://go.googlesource.com/go/+/9cd1818a7d019c02fa4898b3e45a323e35033290","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ","https://pkg.go.dev/vuln/GO-2022-0533"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-29804","description":"Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0477","versionConstraint":"<1.17.11||>=1.18.0-0,<1.18.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0477","fix":{"state":"fixed","versions":["1.17.11","1.18.3"],"available":[{"date":"2022-06-01","kind":"release","version":"1.17.11"},{"date":"2022-06-01","kind":"release","version":"1.18.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30634","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30634","date":"2026-10-08","epss":0.0226,"percentile":0.82442}],"risk":1.695,"urls":["https://go.googlesource.com/go/+/bb1f4416180511231de6d17a1f2f55c82aafc863","https://go.dev/issue/52561","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/402257","description":"On Windows, rand.Read will hang indefinitely if passed a buffer larger than 1 << 32 - 1 bytes."},"relatedVulnerabilities":[{"id":"CVE-2022-30634","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30634","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30634","date":"2026-10-08","epss":0.0226,"percentile":0.82442}],"urls":["https://go.dev/cl/402257","https://go.dev/issue/52561","https://go.googlesource.com/go/+/bb1f4416180511231de6d17a1f2f55c82aafc863","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ","https://pkg.go.dev/vuln/GO-2022-0477"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30634","description":"Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0523","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0523","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30633","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-30633","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-30633","date":"2026-10-08","epss":0.02086,"percentile":0.80996}],"risk":1.5645,"urls":["https://go.googlesource.com/go/+/c4c1993fd2a5b26fe45c09592af6d3388a3b2e08","https://go.dev/issue/53611","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417061","description":"Unmarshaling an XML document into a Go struct which has a nested field that uses the 'any' field tag can panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2022-30633","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30633","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-30633","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-30633","date":"2026-10-08","epss":0.02086,"percentile":0.80996}],"urls":["https://go.dev/cl/417061","https://go.dev/issue/53611","https://go.googlesource.com/go/+/c4c1993fd2a5b26fe45c09592af6d3388a3b2e08","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0523"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30633","description":"Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via unmarshalling an XML document into a Go struct which has a nested field that uses the 'any' field tag."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0522","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0522","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30632","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30632","date":"2026-10-08","epss":0.02069,"percentile":0.80835}],"risk":1.55175,"urls":["https://go.googlesource.com/go/+/ac68c6c683409f98250d34ad282b9e1b0c9095ef","https://go.dev/issue/53416","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417066","description":"Calling Glob on a path which contains a large number of path separators can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2022-30632","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30632","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30632","date":"2026-10-08","epss":0.02069,"percentile":0.80835}],"urls":["https://go.dev/cl/417066","https://go.dev/issue/53416","https://go.googlesource.com/go/+/ac68c6c683409f98250d34ad282b9e1b0c9095ef","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0522"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30632","description":"Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path containing a large number of path separators."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0527","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0527","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30630","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30630","date":"2026-10-08","epss":0.02069,"percentile":0.80835}],"risk":1.55175,"urls":["https://go.googlesource.com/go/+/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59","https://go.dev/issue/53415","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417065","description":"Calling Glob on a path which contains a large number of path separators can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2022-30630","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30630","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30630","date":"2026-10-08","epss":0.02069,"percentile":0.80835}],"urls":["https://go.dev/cl/417065","https://go.dev/issue/53415","https://go.googlesource.com/go/+/fa2d41d0ca736f3ad6b200b2a4e134364e9acc59","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0527"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30630","description":"Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0524","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0524","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30631","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30631","date":"2026-10-08","epss":0.02066,"percentile":0.80798}],"risk":1.5495,"urls":["https://go.googlesource.com/go/+/b2b8872c876201eac2d0707276c6999ff3eb185e","https://go.dev/issue/53168","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417067","description":"Calling Reader.Read on an archive containing a large number of concatenated 0-length compressed files can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2022-30631","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30631","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30631","date":"2026-10-08","epss":0.02066,"percentile":0.80798}],"urls":["https://go.dev/cl/417067","https://go.dev/issue/53168","https://go.googlesource.com/go/+/b2b8872c876201eac2d0707276c6999ff3eb185e","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0524"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30631","description":"Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0493","versionConstraint":"<1.17.10||>=1.18.0-0,<1.18.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0493","fix":{"state":"fixed","versions":["1.17.10","1.18.2"],"available":[{"date":"2022-05-10","kind":"release","version":"1.17.10"},{"date":"2022-05-10","kind":"release","version":"1.18.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29526","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29526","date":"2026-10-08","epss":0.02951,"percentile":0.86767}],"risk":1.5197650000000003,"urls":["https://go.dev/issue/52313","https://go.dev/cl/400074","https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/399539","description":"When called with a non-zero flags parameter, the Faccessat function can incorrectly report that a file is accessible."},"relatedVulnerabilities":[{"id":"CVE-2022-29526","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29526","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29526","date":"2026-10-08","epss":0.02951,"percentile":0.86767}],"urls":["https://github.com/golang/go/issues/52313","https://groups.google.com/g/golang-announce","https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q6GE5EQGE4L2KRVGW4T75QVIYAXCLO5X/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/","https://security.gentoo.org/glsa/202208-02","https://security.netapp.com/advisory/ntap-20220729-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-29526","description":"Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible."},{"id":"GHSA-p782-xgp4-8hr8","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-29526","cwe":"CWE-269","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-29526","date":"2026-10-08","epss":0.02951,"percentile":0.86767}],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-29526","https://github.com/golang/go/issues/52313","https://groups.google.com/g/golang-announce","https://groups.google.com/g/golang-announce/c/Y5qrqw_lWdU","https://security.gentoo.org/glsa/202208-02","https://go.dev/cl/399539","https://go.dev/cl/400074","https://go.dev/issue/52313","https://pkg.go.dev/vuln/GO-2022-0493","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q6GE5EQGE4L2KRVGW4T75QVIYAXCLO5X","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR","https://security.netapp.com/advisory/ntap-20220729-0001"],"severity":"Medium","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-p782-xgp4-8hr8","description":"golang.org/x/sys/unix has Incorrect privilege reporting in syscall"}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1752","versionConstraint":"<1.19.9||>=1.20.0-0,<1.20.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1752","fix":{"state":"fixed","versions":["1.19.9","1.20.4"],"available":[{"date":"2023-05-02","kind":"release","version":"1.19.9"},{"date":"2023-05-02","kind":"release","version":"1.20.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24540","cwe":"CWE-77","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24540","date":"2026-10-08","epss":0.0156,"percentile":0.74484}],"risk":1.4664,"urls":["https://go.dev/cl/491616","https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/59721","description":"Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set \"\\t\\n\\f\\r\\u0020\\u2028\\u2029\" in JavaScript contexts that also contain actions may not be properly sanitized during execution."},"relatedVulnerabilities":[{"id":"CVE-2023-24540","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24540","cwe":"CWE-77","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24540","date":"2026-10-08","epss":0.0156,"percentile":0.74484}],"urls":["https://go.dev/cl/491616","https://go.dev/issue/59721","https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU","https://pkg.go.dev/vuln/GO-2023-1752","https://security.netapp.com/advisory/ntap-20241115-0008/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24540","description":"Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set \"\\t\\n\\f\\r\\u0020\\u2028\\u2029\" in JavaScript contexts that also contain actions may not be properly sanitized during execution."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-21441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-21441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-21441","date":"2026-10-08","epss":0.02922,"percentile":0.86636}],"risk":1.461,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-21441"},"relatedVulnerabilities":[{"id":"CVE-2026-21441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-21441","date":"2026-10-08","epss":0.02922,"percentile":0.86636}],"urls":["https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b","https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99","https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html","https://access.redhat.com/errata/RHSA-2026:0981","https://access.redhat.com/errata/RHSA-2026:0990","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:1038","https://access.redhat.com/errata/RHSA-2026:1041","https://access.redhat.com/errata/RHSA-2026:1042","https://access.redhat.com/errata/RHSA-2026:1086","https://access.redhat.com/errata/RHSA-2026:1087","https://access.redhat.com/errata/RHSA-2026:1088","https://access.redhat.com/errata/RHSA-2026:1089","https://access.redhat.com/errata/RHSA-2026:1166","https://access.redhat.com/errata/RHSA-2026:1168","https://access.redhat.com/errata/RHSA-2026:1176","https://access.redhat.com/errata/RHSA-2026:1224","https://access.redhat.com/errata/RHSA-2026:1226","https://access.redhat.com/errata/RHSA-2026:1239","https://access.redhat.com/errata/RHSA-2026:1240","https://access.redhat.com/errata/RHSA-2026:1241","https://access.redhat.com/errata/RHSA-2026:1254","https://access.redhat.com/errata/RHSA-2026:1485","https://access.redhat.com/errata/RHSA-2026:14877","https://access.redhat.com/errata/RHSA-2026:1504","https://access.redhat.com/errata/RHSA-2026:1546","https://access.redhat.com/errata/RHSA-2026:1596","https://access.redhat.com/errata/RHSA-2026:1599","https://access.redhat.com/errata/RHSA-2026:1609","https://access.redhat.com/errata/RHSA-2026:1618","https://access.redhat.com/errata/RHSA-2026:1619","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:1674","https://access.redhat.com/errata/RHSA-2026:1676","https://access.redhat.com/errata/RHSA-2026:1693","https://access.redhat.com/errata/RHSA-2026:1704","https://access.redhat.com/errata/RHSA-2026:1706","https://access.redhat.com/errata/RHSA-2026:1712","https://access.redhat.com/errata/RHSA-2026:1717","https://access.redhat.com/errata/RHSA-2026:1726","https://access.redhat.com/errata/RHSA-2026:1729","https://access.redhat.com/errata/RHSA-2026:1730","https://access.redhat.com/errata/RHSA-2026:1734","https://access.redhat.com/errata/RHSA-2026:1735","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:17456","https://access.redhat.com/errata/RHSA-2026:17457","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17461","https://access.redhat.com/errata/RHSA-2026:17462","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:1791","https://access.redhat.com/errata/RHSA-2026:1792","https://access.redhat.com/errata/RHSA-2026:1793","https://access.redhat.com/errata/RHSA-2026:1794","https://access.redhat.com/errata/RHSA-2026:1803","https://access.redhat.com/errata/RHSA-2026:1805","https://access.redhat.com/errata/RHSA-2026:1942","https://access.redhat.com/errata/RHSA-2026:1957","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:2106","https://access.redhat.com/errata/RHSA-2026:2126","https://access.redhat.com/errata/RHSA-2026:2137","https://access.redhat.com/errata/RHSA-2026:2139","https://access.redhat.com/errata/RHSA-2026:2144","https://access.redhat.com/errata/RHSA-2026:2256","https://access.redhat.com/errata/RHSA-2026:2456","https://access.redhat.com/errata/RHSA-2026:2500","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2695","https://access.redhat.com/errata/RHSA-2026:2717","https://access.redhat.com/errata/RHSA-2026:2718","https://access.redhat.com/errata/RHSA-2026:2723","https://access.redhat.com/errata/RHSA-2026:2728","https://access.redhat.com/errata/RHSA-2026:2760","https://access.redhat.com/errata/RHSA-2026:2762","https://access.redhat.com/errata/RHSA-2026:2764","https://access.redhat.com/errata/RHSA-2026:2765","https://access.redhat.com/errata/RHSA-2026:28043","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:2900","https://access.redhat.com/errata/RHSA-2026:2911","https://access.redhat.com/errata/RHSA-2026:2919","https://access.redhat.com/errata/RHSA-2026:2924","https://access.redhat.com/errata/RHSA-2026:2925","https://access.redhat.com/errata/RHSA-2026:2926","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:33154","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:3444","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:4185","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:4215","https://access.redhat.com/errata/RHSA-2026:4271","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:44696","https://access.redhat.com/errata/RHSA-2026:51357","https://access.redhat.com/errata/RHSA-2026:5459","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:6287","https://access.redhat.com/errata/RHSA-2026:6292","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8500","https://access.redhat.com/errata/RHSA-2026:8501","https://access.redhat.com/security/cve/CVE-2026-21441","https://bugzilla.redhat.com/show_bug.cgi?id=2427726","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441","description":"urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1704","versionConstraint":"<1.19.8||>=1.20.0-0,<1.20.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1704","fix":{"state":"fixed","versions":["1.19.8","1.20.3"],"available":[{"date":"2023-04-04","kind":"release","version":"1.19.8"},{"date":"2023-04-04","kind":"release","version":"1.20.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24534","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24534","date":"2026-10-08","epss":0.01888,"percentile":0.78902}],"risk":1.4160000000000001,"urls":["https://go.dev/cl/481994","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/58975","description":"HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service.\n\nCertain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service.\n\nWith fix, header parsing now correctly allocates only the memory required to hold parsed headers."},"relatedVulnerabilities":[{"id":"CVE-2023-24534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24534","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24534","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24534","date":"2026-10-08","epss":0.01888,"percentile":0.78902}],"urls":["https://go.dev/cl/481994","https://go.dev/issue/58975","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8","https://pkg.go.dev/vuln/GO-2023-1704","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20230526-0007/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24534","description":"HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more memory than required to hold the parsed headers. An attacker can exploit this behavior to cause an HTTP server to allocate large amounts of memory from a small request, potentially leading to memory exhaustion and a denial of service. With fix, header parsing now correctly allocates only the memory required to hold parsed headers."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0526","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0526","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30635","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-30635","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-30635","date":"2026-10-08","epss":0.0181,"percentile":0.77961}],"risk":1.3575,"urls":["https://go.googlesource.com/go/+/6fa37e98ea4382bf881428ee0c150ce591500eb7","https://go.dev/issue/53615","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417064","description":"Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2022-30635","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30635","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-30635","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-30635","date":"2026-10-08","epss":0.0181,"percentile":0.77961}],"urls":["https://go.dev/cl/417064","https://go.dev/issue/53615","https://go.googlesource.com/go/+/6fa37e98ea4382bf881428ee0c150ce591500eb7","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30635","description":"Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a message which contains deeply nested structures."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1568","versionConstraint":"<1.19.6||>=1.20.0-0,<1.20.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1568","fix":{"state":"fixed","versions":["1.19.6","1.20.1"],"available":[{"date":"2023-02-14","kind":"release","version":"1.19.6"},{"date":"2023-02-14","kind":"release","version":"1.20.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41722","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41722","date":"2026-10-08","epss":0.01678,"percentile":0.76195}],"risk":1.2585,"urls":["https://go.dev/cl/468123","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/57274","description":"A path traversal vulnerability exists in filepath.Clean on Windows.\n\nOn Windows, the filepath.Clean function could transform an invalid path such as \"a/../c:/b\" into the valid path \"c:\\b\". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack.\n\nAfter fix, the filepath.Clean function transforms this path into the relative (but still invalid) path \".\\c:\\b\"."},"relatedVulnerabilities":[{"id":"CVE-2022-41722","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41722","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41722","date":"2026-10-08","epss":0.01678,"percentile":0.76195}],"urls":["https://go.dev/cl/468123","https://go.dev/issue/57274","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E","https://pkg.go.dev/vuln/GO-2023-1568"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41722","description":"A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as \"a/../c:/b\" into the valid path \"c:\\b\". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path \".\\c:\\b\"."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-1037","versionConstraint":"<1.18.7||>=1.19.0-0,<1.19.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-1037","fix":{"state":"fixed","versions":["1.18.7","1.19.2"],"available":[{"date":"2022-10-04","kind":"release","version":"1.18.7"},{"date":"2022-10-04","kind":"release","version":"1.19.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2879","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2879","date":"2026-10-08","epss":0.01667,"percentile":0.76048}],"risk":1.2502499999999999,"urls":["https://go.dev/cl/439355","https://groups.google.com/g/golang-announce/c/xtuG5faxtaU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/54853","description":"Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB."},"relatedVulnerabilities":[{"id":"CVE-2022-2879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2879","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2879","date":"2026-10-08","epss":0.01667,"percentile":0.76048}],"urls":["https://go.dev/cl/439355","https://go.dev/issue/54853","https://groups.google.com/g/golang-announce/c/xtuG5faxtaU","https://pkg.go.dev/vuln/GO-2022-1037","https://security.gentoo.org/glsa/202311-09"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2879","description":"Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 MiB."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1705","versionConstraint":"<1.19.8||>=1.20.0-0,<1.20.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1705","fix":{"state":"fixed","versions":["1.19.8","1.20.3"],"available":[{"date":"2023-04-04","kind":"release","version":"1.19.8"},{"date":"2023-04-04","kind":"release","version":"1.20.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24536","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24536","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24536","date":"2026-10-08","epss":0.01479,"percentile":0.73108}],"risk":1.10925,"urls":["https://go.dev/cl/482076","https://go.dev/cl/482075","https://go.dev/cl/482077","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/59153","description":"Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts.\n\nThis stems from several causes:\n\n1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can undercount the amount of memory consumed, leading it to accept larger inputs than intended.\n2. Limiting total memory does not account for increased pressure on the garbage collector from large numbers of small allocations in forms with many parts.\n3. ReadForm can allocate a large number of short-lived buffers, further increasing pressure on the garbage collector.\n\nThe combination of these factors can permit an attacker to cause an program that parses multipart forms to consume large amounts of CPU and memory, potentially resulting in a denial of service. This affects programs that use mime/multipart.Reader.ReadForm, as well as form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue.\n\nWith fix, ReadForm now does a better job of estimating the memory consumption of parsed forms, and performs many fewer short-lived allocations.\n\nIn addition, the fixed mime/multipart.Reader imposes the following limits on the size of parsed forms:\n\n1. Forms parsed with ReadForm may contain no more than 1000 parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxparts=.\n2. Form parts parsed with NextPart and NextRawPart may contain no more than 10,000 header fields. In addition, forms parsed with ReadForm may contain no more than 10,000 header fields across all parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxheaders=."},"relatedVulnerabilities":[{"id":"CVE-2023-24536","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24536","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24536","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24536","date":"2026-10-08","epss":0.01479,"percentile":0.73108}],"urls":["https://go.dev/cl/482075","https://go.dev/cl/482076","https://go.dev/cl/482077","https://go.dev/issue/59153","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8","https://pkg.go.dev/vuln/GO-2023-1705","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20230526-0007/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24536","description":"Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can undercount the amount of memory consumed, leading it to accept larger inputs than intended. 2. Limiting total memory does not account for increased pressure on the garbage collector from large numbers of small allocations in forms with many parts. 3. ReadForm can allocate a large number of short-lived buffers, further increasing pressure on the garbage collector. The combination of these factors can permit an attacker to cause an program that parses multipart forms to consume large amounts of CPU and memory, potentially resulting in a denial of service. This affects programs that use mime/multipart.Reader.ReadForm, as well as form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. With fix, ReadForm now does a better job of estimating the memory consumption of parsed forms, and performs many fewer short-lived allocations. In addition, the fixed mime/multipart.Reader imposes the following limits on the size of parsed forms: 1. Forms parsed with ReadForm may contain no more than 1000 parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxparts=. 2. Form parts parsed with NextPart and NextRawPart may contain no more than 10,000 header fields. In addition, forms parsed with ReadForm may contain no more than 10,000 header fields across all parts. This limit may be adjusted with the environment variable GODEBUG=multipartmaxheaders=."}]},{"artifact":{"id":"2c249697e195b912","cpes":["cpe:2.3:a:golang:text:v0.3.6:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.3.6","type":"go-module","version":"v0.3.6","language":"go","licenses":[],"metadata":{"h1Digest":"h1:aRYxNxv6iGQlyVaZmk6ZgYEDa+Jg18DxebPSrd6bg1M=","mainModule":"github.com/pgaskin/kepubify/v4","architecture":"x86_64","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.3.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-69ch-w2m2-3vjp","versionConstraint":"<0.3.8 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.3.6"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-69ch-w2m2-3vjp","fix":{"state":"fixed","versions":["0.3.8"],"available":[{"date":"2023-02-23","kind":"first-observed","version":"0.3.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32149","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32149","date":"2026-10-08","epss":0.01474,"percentile":0.7303}],"risk":1.1055,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2022-32149","https://go.dev/cl/442235","https://go.dev/issue/56152","https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ","https://pkg.go.dev/vuln/GO-2022-1059","https://github.com/golang/go/issues/56152","https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c","https://security.netapp.com/advisory/ntap-20230203-0006"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-69ch-w2m2-3vjp","description":"golang.org/x/text/language Denial of service via crafted Accept-Language header"},"relatedVulnerabilities":[{"id":"CVE-2022-32149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-32149","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-32149","date":"2026-10-08","epss":0.01474,"percentile":0.7303}],"urls":["https://go.dev/cl/442235","https://go.dev/issue/56152","https://groups.google.com/g/golang-announce/c/-hjNw559_tE/m/KlGTfid5CAAJ","https://pkg.go.dev/vuln/GO-2022-1059","https://security.netapp.com/advisory/ntap-20230203-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32149","description":"An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take significant time to parse."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-1039","versionConstraint":"<1.18.7||>=1.19.0-0,<1.19.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-1039","fix":{"state":"fixed","versions":["1.18.7","1.19.2"],"available":[{"date":"2022-10-04","kind":"release","version":"1.18.7"},{"date":"2022-10-04","kind":"release","version":"1.19.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41715","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41715","date":"2026-10-08","epss":0.01434,"percentile":0.72295}],"risk":1.0755000000000001,"urls":["https://go.dev/cl/439356","https://groups.google.com/g/golang-announce/c/xtuG5faxtaU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/55949","description":"Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service.\n\nThe parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory.\n\nAfter fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected."},"relatedVulnerabilities":[{"id":"CVE-2022-41715","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41715","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41715","date":"2026-10-08","epss":0.01434,"percentile":0.72295}],"urls":["https://go.dev/cl/439356","https://go.dev/issue/55949","https://groups.google.com/g/golang-announce/c/xtuG5faxtaU","https://pkg.go.dev/vuln/GO-2022-1039","https://security.gentoo.org/glsa/202311-09"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41715","description":"Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small regexps consume much larger amounts of memory. After fix, each regexp being parsed is limited to a 256 MB memory footprint. Regular expressions whose representation would use more space than that are rejected. Normal use of regular expressions is unaffected."}]},{"artifact":{"id":"2c249697e195b912","cpes":["cpe:2.3:a:golang:text:v0.3.6:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.3.6","type":"go-module","version":"v0.3.6","language":"go","licenses":[],"metadata":{"h1Digest":"h1:aRYxNxv6iGQlyVaZmk6ZgYEDa+Jg18DxebPSrd6bg1M=","mainModule":"github.com/pgaskin/kepubify/v4","architecture":"x86_64","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.3.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ppp9-7jff-5vj2","versionConstraint":"<0.3.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.3.6"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-ppp9-7jff-5vj2","fix":{"state":"fixed","versions":["0.3.7"],"available":[{"date":"2023-02-26","kind":"first-observed","version":"0.3.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-38561","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-38561","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-38561","date":"2026-10-08","epss":0.0143,"percentile":0.72232}],"risk":1.0725,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-38561","https://deps.dev/advisory/OSV/GO-2021-0113","https://go.googlesource.com/text/+/383b2e75a7a4198c42f8f87833eefb772868a56f","https://groups.google.com/g/golang-announce","https://pkg.go.dev/golang.org/x/text/language","https://go.dev/cl/340830","https://pkg.go.dev/vuln/GO-2021-0113"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ppp9-7jff-5vj2","description":"golang.org/x/text/language Out-of-bounds Read vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2021-38561","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-38561","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-38561","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2021-38561","date":"2026-10-08","epss":0.0143,"percentile":0.72232}],"urls":["https://deps.dev/advisory/OSV/GO-2021-0113","https://go.googlesource.com/text/+/383b2e75a7a4198c42f8f87833eefb772868a56f","https://groups.google.com/g/golang-announce","https://pkg.go.dev/golang.org/x/text/language"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-38561","description":"golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language tag parsing. Index calculation is mishandled. If parsing untrusted user input, this can be used as a vector for a denial-of-service attack."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2963","versionConstraint":"<1.21.12||>=1.22.0-0,<1.22.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2963","fix":{"state":"fixed","versions":["1.21.12","1.22.5"],"available":[{"date":"2024-07-02","kind":"release","version":"1.21.12"},{"date":"2024-07-02","kind":"release","version":"1.22.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24791","date":"2026-10-08","epss":0.01414,"percentile":0.71922}],"risk":1.0605,"urls":["https://go.dev/issue/67555","https://groups.google.com/g/golang-dev/c/t0rK-qHBqzY/m/6MMoAZkMAgAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/591255","description":"The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an \"Expect: 100-continue\" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail.\n\nAn attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending \"Expect: 100-continue\" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail."},"relatedVulnerabilities":[{"id":"CVE-2024-24791","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24791","date":"2026-10-08","epss":0.01414,"percentile":0.71922}],"urls":["https://go.dev/cl/591255","https://go.dev/issue/67555","https://groups.google.com/g/golang-dev/c/t0rK-qHBqzY/m/6MMoAZkMAgAJ","https://pkg.go.dev/vuln/GO-2024-2963","https://security.netapp.com/advisory/ntap-20241004-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24791","description":"The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an \"Expect: 100-continue\" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending \"Expect: 100-continue\" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1702","versionConstraint":"<1.19.8||>=1.20.0-0,<1.20.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1702","fix":{"state":"fixed","versions":["1.19.8","1.20.3"],"available":[{"date":"2023-04-04","kind":"release","version":"1.19.8"},{"date":"2023-04-04","kind":"release","version":"1.20.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24537","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24537","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24537","date":"2026-10-08","epss":0.01412,"percentile":0.71885}],"risk":1.059,"urls":["https://go.dev/cl/482078","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/59180","description":"Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow."},"relatedVulnerabilities":[{"id":"CVE-2023-24537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24537","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24537","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24537","date":"2026-10-08","epss":0.01412,"percentile":0.71885}],"urls":["https://go.dev/cl/482078","https://go.dev/issue/59180","https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8","https://pkg.go.dev/vuln/GO-2023-1702","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20241129-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24537","description":"Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-46522","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46522","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"risk":0.967,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46522"},"relatedVulnerabilities":[{"id":"CVE-2026-46522","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7gg8-qqx7-92g5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46522","https://bugzilla.redhat.com/show_bug.cgi?id=2487730","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46522.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46522","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46522","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46522","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"risk":0.967,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46522"},"relatedVulnerabilities":[{"id":"CVE-2026-46522","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7gg8-qqx7-92g5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46522","https://bugzilla.redhat.com/show_bug.cgi?id=2487730","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46522.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46522","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46522","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46522","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"risk":0.967,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46522"},"relatedVulnerabilities":[{"id":"CVE-2026-46522","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7gg8-qqx7-92g5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46522","https://bugzilla.redhat.com/show_bug.cgi?id=2487730","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46522.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46522","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46522","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46522","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"risk":0.967,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46522"},"relatedVulnerabilities":[{"id":"CVE-2026-46522","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7gg8-qqx7-92g5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46522","https://bugzilla.redhat.com/show_bug.cgi?id=2487730","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46522.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46522","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46522","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46522","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"risk":0.967,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46522"},"relatedVulnerabilities":[{"id":"CVE-2026-46522","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46522","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46522","cwe":"CWE-835","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46522","date":"2026-10-08","epss":0.01934,"percentile":0.79443}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7gg8-qqx7-92g5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46522","https://bugzilla.redhat.com/show_bug.cgi?id=2487730","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46522.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46522","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file could cause an infinite loop resulting in CPU exhaustion. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-1143","versionConstraint":"<1.18.9||>=1.19.0-0,<1.19.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-1143","fix":{"state":"fixed","versions":["1.18.9","1.19.4"],"available":[{"date":"2022-12-06","kind":"release","version":"1.18.9"},{"date":"2022-12-06","kind":"release","version":"1.19.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41720","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41720","date":"2026-10-08","epss":0.01279,"percentile":0.69124}],"risk":0.95925,"urls":["https://go.dev/cl/455716","https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/56694","description":"On Windows, restricted files can be accessed via os.DirFS and http.Dir.\n\nThe os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS(\"C:/tmp\").Open(\"COM1\") opens the COM1 device. Both os.DirFS and http.Dir only provide read-only filesystem access.\n\nIn addition, on Windows, an os.DirFS for the directory (the root of the current drive) can permit a maliciously crafted path to escape from the drive and access any path on the system.\n\nWith fix applied, the behavior of os.DirFS(\"\") has changed. Previously, an empty root was treated equivalently to \"/\", so os.DirFS(\"\").Open(\"tmp\") would open the path \"/tmp\". This now returns an error."},"relatedVulnerabilities":[{"id":"CVE-2022-41720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41720","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41720","date":"2026-10-08","epss":0.01279,"percentile":0.69124}],"urls":["https://go.dev/cl/455716","https://go.dev/issue/56694","https://groups.google.com/g/golang-announce/c/L_3rmdT0BMU/m/yZDrXjIiBQAJ","https://pkg.go.dev/vuln/GO-2022-1143"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41720","description":"On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, os.DirFS(\"C:/tmp\").Open(\"COM1\") opens the COM1 device. Both os.DirFS and http.Dir only provide read-only filesystem access. In addition, on Windows, an os.DirFS for the directory (the root of the current drive) can permit a maliciously crafted path to escape from the drive and access any path on the system. With fix applied, the behavior of os.DirFS(\"\") has changed. Previously, an empty root was treated equivalently to \"/\", so os.DirFS(\"\").Open(\"tmp\") would open the path \"/tmp\". This now returns an error."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.20.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-2375","versionConstraint":"<1.20.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-2375","fix":{"state":"fixed","versions":["1.20.0"],"available":[{"date":"2023-02-01","kind":"release","version":"1.20.0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45287","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45287","date":"2026-10-08","epss":0.0125,"percentile":0.68497}],"risk":0.9375000000000001,"urls":["https://go.dev/cl/326012/26","https://groups.google.com/g/golang-announce/c/QMK8IQALDvA","https://people.redhat.com/~hkario/marvin/"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/20654","description":"Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits.\n\nIn Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels."},"relatedVulnerabilities":[{"id":"CVE-2023-45287","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45287","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45287","date":"2026-10-08","epss":0.0125,"percentile":0.68497}],"urls":["https://go.dev/cl/326012/26","https://go.dev/issue/20654","https://groups.google.com/g/golang-announce/c/QMK8IQALDvA","https://people.redhat.com/~hkario/marvin/","https://pkg.go.dev/vuln/GO-2023-2375","https://security.netapp.com/advisory/ntap-20240112-0005/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45287","description":"Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1569","versionConstraint":"<1.19.6||>=1.20.0-0,<1.20.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1569","fix":{"state":"fixed","versions":["1.19.6","1.20.1"],"available":[{"date":"2023-02-14","kind":"release","version":"1.19.6"},{"date":"2023-02-14","kind":"release","version":"1.20.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41725","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41725","date":"2026-10-08","epss":0.01241,"percentile":0.68283}],"risk":0.93075,"urls":["https://go.dev/cl/468124","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/58006","description":"A denial of service is possible from excessive resource consumption in net/http and mime/multipart.\n\nMultipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue.\n\nReadForm takes a maxMemory parameter, and is documented as storing \"up to maxMemory bytes +10MB (reserved for non-file parts) in memory\". File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did not properly account for all memory consumed by a parsed form, such as map entry overhead, part names, and MIME headers, permitting a maliciously crafted form to consume well over 10MB. In addition, ReadForm contained no limit on the number of disk files created, permitting a relatively small request body to create a large number of disk temporary files.\n\nWith fix, ReadForm now properly accounts for various forms of memory overhead, and should now stay within its documented limit of 10MB + maxMemory bytes of memory consumption. Users should still be aware that this limit is high and may still be hazardous.\n\nIn addition, ReadForm now creates at most one on-disk temporary file, combining multiple form parts into a single temporary file. The mime/multipart.File interface type's documentation states, \"If stored on disk, the File's underlying concrete type will be an *os.File.\". This is no longer the case when a form contains more than one file part, due to this coalescing of parts into a single file. The previous behavior of using distinct files for each form part may be reenabled with the environment variable GODEBUG=multipartfiles=distinct.\n\nUsers should be aware that multipart.ReadForm and the http.Request methods that call it do not limit the amount of disk consumed by temporary files. Callers can limit the size of form data with http.MaxBytesReader."},"relatedVulnerabilities":[{"id":"CVE-2022-41725","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41725","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41725","date":"2026-10-08","epss":0.01241,"percentile":0.68283}],"urls":["https://go.dev/cl/468124","https://go.dev/issue/58006","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E","https://pkg.go.dev/vuln/GO-2023-1569","https://security.gentoo.org/glsa/202311-09"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41725","description":"A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing \"up to maxMemory bytes +10MB (reserved for non-file parts) in memory\". File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did not properly account for all memory consumed by a parsed form, such as map entry overhead, part names, and MIME headers, permitting a maliciously crafted form to consume well over 10MB. In addition, ReadForm contained no limit on the number of disk files created, permitting a relatively small request body to create a large number of disk temporary files. With fix, ReadForm now properly accounts for various forms of memory overhead, and should now stay within its documented limit of 10MB + maxMemory bytes of memory consumption. Users should still be aware that this limit is high and may still be hazardous. In addition, ReadForm now creates at most one on-disk temporary file, combining multiple form parts into a single temporary file. The mime/multipart.File interface type's documentation states, \"If stored on disk, the File's underlying concrete type will be an *os.File.\". This is no longer the case when a form contains more than one file part, due to this coalescing of parts into a single file. The previous behavior of using distinct files for each form part may be reenabled with the environment variable GODEBUG=multipartfiles=distinct. Users should be aware that multipart.ReadForm and the http.Request methods that call it do not limit the amount of disk consumed by temporary files. Callers can limit the size of form data with http.MaxBytesReader."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-1038","versionConstraint":"<1.18.7||>=1.19.0-0,<1.19.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-1038","fix":{"state":"fixed","versions":["1.18.7","1.19.2"],"available":[{"date":"2022-10-04","kind":"release","version":"1.18.7"},{"date":"2022-10-04","kind":"release","version":"1.19.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2880","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2880","date":"2026-10-08","epss":0.0117,"percentile":0.6644}],"risk":0.8775,"urls":["https://go.dev/cl/432976","https://groups.google.com/g/golang-announce/c/xtuG5faxtaU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/54663","description":"Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value.\n\nAfter fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged."},"relatedVulnerabilities":[{"id":"CVE-2022-2880","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-2880","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-2880","date":"2026-10-08","epss":0.0117,"percentile":0.6644}],"urls":["https://go.dev/cl/432976","https://go.dev/issue/54663","https://groups.google.com/g/golang-announce/c/xtuG5faxtaU","https://pkg.go.dev/vuln/GO-2022-1038","https://security.gentoo.org/glsa/202311-09"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-2880","description":"Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4337","versionConstraint":"<1.24.13||>=1.25.0-0,<1.25.7||>=1.26.0-rc.1,<1.26.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4337","fix":{"state":"fixed","versions":["1.24.13","1.25.7","1.26.0-rc.3"],"available":[{"date":"2026-02-04","kind":"release","version":"1.24.13"},{"date":"2026-02-04","kind":"release","version":"1.25.7"},{"date":"2026-02-04","kind":"release","version":"1.26.0-rc.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"risk":0.8692500000000001,"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-68121","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217","https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","https://pkg.go.dev/vuln/GO-2026-4337"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68121","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-3106","versionConstraint":"<1.22.7||>=1.23.0-0,<1.23.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-3106","fix":{"state":"fixed","versions":["1.22.7","1.23.1"],"available":[{"date":"2024-09-05","kind":"release","version":"1.22.7"},{"date":"2024-09-05","kind":"release","version":"1.23.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34156","date":"2026-10-08","epss":0.01127,"percentile":0.65326}],"risk":0.84525,"urls":["https://go.dev/issue/69139","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/611239","description":"Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635."},"relatedVulnerabilities":[{"id":"CVE-2024-34156","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34156","date":"2026-10-08","epss":0.01127,"percentile":0.65326}],"urls":["https://go.dev/cl/611239","https://go.dev/issue/69139","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk","https://pkg.go.dev/vuln/GO-2024-3106","https://security.netapp.com/advisory/ntap-20240926-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34156","description":"Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1878","versionConstraint":"<1.19.11||>=1.20.0-0,<1.20.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1878","fix":{"state":"fixed","versions":["1.19.11","1.20.6"],"available":[{"date":"2023-07-11","kind":"release","version":"1.19.11"},{"date":"2023-07-11","kind":"release","version":"1.20.6"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29406","cwe":"CWE-436","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29406","date":"2026-10-08","epss":0.01453,"percentile":0.72634}],"risk":0.835475,"urls":["https://go.dev/cl/506996","https://groups.google.com/g/golang-announce/c/2q13H6LEEx0"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/60374","description":"The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests.\n\nWith fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value."},"relatedVulnerabilities":[{"id":"CVE-2023-29406","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29406","cwe":"CWE-436","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29406","date":"2026-10-08","epss":0.01453,"percentile":0.72634}],"urls":["https://go.dev/cl/506996","https://go.dev/issue/60374","https://groups.google.com/g/golang-announce/c/2q13H6LEEx0","https://pkg.go.dev/vuln/GO-2023-1878","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20230814-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29406","description":"The HTTP/1 client does not fully validate the contents of the Host header. A maliciously crafted Host header can inject additional headers or entire requests. With fix, the HTTP/1 client now refuses to send requests containing an invalid Request.Host or Request.URL.Host value."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1570","versionConstraint":"<1.19.6||>=1.20.0-0,<1.20.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1570","fix":{"state":"fixed","versions":["1.19.6","1.20.1"],"available":[{"date":"2023-02-14","kind":"release","version":"1.19.6"},{"date":"2023-02-14","kind":"release","version":"1.20.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41724","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41724","date":"2026-10-08","epss":0.01111,"percentile":0.64924}],"risk":0.8332499999999999,"urls":["https://go.dev/cl/468125","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/58001","description":"Large handshake records may cause panics in crypto/tls.\n\nBoth clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses.\n\nThis affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert)."},"relatedVulnerabilities":[{"id":"CVE-2022-41724","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41724","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41724","date":"2026-10-08","epss":0.01111,"percentile":0.64924}],"urls":["https://go.dev/cl/468125","https://go.dev/issue/58001","https://groups.google.com/g/golang-announce/c/V0aBFqaFs_E","https://pkg.go.dev/vuln/GO-2023-1570","https://security.gentoo.org/glsa/202311-09"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41724","description":"Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert)."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0525","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0525","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1705","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1705","date":"2026-10-08","epss":0.01447,"percentile":0.72518}],"risk":0.8320249999999999,"urls":["https://go.googlesource.com/go/+/e5017a93fcde94f09836200bca55324af037ee5f","https://go.dev/issue/53188","https://go.dev/cl/410714","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/409874","description":"The HTTP/1 client accepted some invalid Transfer-Encoding headers as indicating a \"chunked\" encoding. This could potentially allow for request smuggling, but only if combined with an intermediate server that also improperly failed to reject the header as invalid."},"relatedVulnerabilities":[{"id":"CVE-2022-1705","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1705","cwe":"CWE-444","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1705","date":"2026-10-08","epss":0.01447,"percentile":0.72518}],"urls":["https://go.dev/cl/409874","https://go.dev/cl/410714","https://go.dev/issue/53188","https://go.googlesource.com/go/+/e5017a93fcde94f09836200bca55324af037ee5f","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0525"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1705","description":"Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0520","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0520","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-32148","date":"2026-10-08","epss":0.01434,"percentile":0.72282}],"risk":0.8245499999999999,"urls":["https://go.googlesource.com/go/+/b2cc0fecc2ccd80e6d5d16542cc684f97b3a9c8a","https://go.dev/issue/53423","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/412857","description":"Client IP adresses may be unintentionally exposed via X-Forwarded-For headers.\n\nWhen httputil.ReverseProxy.ServeHTTP is called with a Request.Header map containing a nil value for the X-Forwarded-For header, ReverseProxy sets the client IP as the value of the X-Forwarded-For header, contrary to its documentation.\n\nIn the more usual case where a Director function sets the X-Forwarded-For header value to nil, ReverseProxy leaves the header unmodified as expected."},"relatedVulnerabilities":[{"id":"CVE-2022-32148","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2022-32148","date":"2026-10-08","epss":0.01434,"percentile":0.72282}],"urls":["https://go.dev/cl/412857","https://go.dev/issue/53423","https://go.googlesource.com/go/+/b2cc0fecc2ccd80e6d5d16542cc684f97b3a9c8a","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0520"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-32148","description":"Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputil.ReverseProxy.ServeHTTP with a Request.Header map containing a nil value for the X-Forwarded-For header, which causes ReverseProxy to set the client IP as the value of the X-Forwarded-For header."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1987","versionConstraint":"<1.19.12||>=1.20.0-0,<1.20.7||>=1.21.0-0,<1.21.0-rc.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1987","fix":{"state":"fixed","versions":["1.19.12","1.20.7","1.21.0-rc.4"],"available":[{"date":"2023-08-01","kind":"release","version":"1.19.12"},{"date":"2023-08-01","kind":"release","version":"1.20.7"},{"date":"2023-08-02","kind":"release","version":"1.21.0-rc.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29409","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29409","date":"2026-10-08","epss":0.01601,"percentile":0.75059}],"risk":0.824515,"urls":["https://go.dev/cl/515257","https://groups.google.com/g/golang-announce/c/X0b6CsSAaYI/m/Efv5DbZ9AwAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/61460","description":"Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures.\n\nWith fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits.\n\nBased on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable."},"relatedVulnerabilities":[{"id":"CVE-2023-29409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29409","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29409","date":"2026-10-08","epss":0.01601,"percentile":0.75059}],"urls":["https://go.dev/cl/515257","https://go.dev/issue/61460","https://groups.google.com/g/golang-announce/c/X0b6CsSAaYI/m/Efv5DbZ9AwAJ","https://pkg.go.dev/vuln/GO-2023-1987","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20230831-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29409","description":"Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56379","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56379","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"risk":0.8215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56379"},"relatedVulnerabilities":[{"id":"CVE-2026-56379","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56","https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-56379","https://bugzilla.redhat.com/show_bug.cgi?id=2491700","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56379","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56379","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56379","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"risk":0.8215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56379"},"relatedVulnerabilities":[{"id":"CVE-2026-56379","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56","https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-56379","https://bugzilla.redhat.com/show_bug.cgi?id=2491700","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56379","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56379","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56379","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"risk":0.8215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56379"},"relatedVulnerabilities":[{"id":"CVE-2026-56379","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56","https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-56379","https://bugzilla.redhat.com/show_bug.cgi?id=2491700","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56379","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56379","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56379","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"risk":0.8215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56379"},"relatedVulnerabilities":[{"id":"CVE-2026-56379","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56","https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-56379","https://bugzilla.redhat.com/show_bug.cgi?id=2491700","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56379","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56379","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56379","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"risk":0.8215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56379"},"relatedVulnerabilities":[{"id":"CVE-2026-56379","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56379","cwe":"CWE-116","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-56379","cwe":"CWE-78","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-56379","date":"2026-10-08","epss":0.01643,"percentile":0.75696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xpg8-7m6m-jf56","https://www.vulncheck.com/advisories/imagemagick-command-injection-via-svg-decoder","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-56379","https://bugzilla.redhat.com/show_bug.cgi?id=2491700","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-56379.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56379","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2609","versionConstraint":"<1.21.8||>=1.22.0-0,<1.22.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2609","fix":{"state":"fixed","versions":["1.21.8","1.22.1"],"available":[{"date":"2024-03-05","kind":"release","version":"1.21.8"},{"date":"2024-03-05","kind":"release","version":"1.22.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24784","date":"2026-10-08","epss":0.0105,"percentile":0.63221}],"risk":0.7875,"urls":["https://go.dev/cl/555596","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/65083","description":"The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers."},"relatedVulnerabilities":[{"id":"CVE-2024-24784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24784","date":"2026-10-08","epss":0.0105,"percentile":0.63221}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/08/4","https://go.dev/cl/555596","https://go.dev/issue/65083","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg","https://pkg.go.dev/vuln/GO-2024-2609","https://security.netapp.com/advisory/ntap-20240329-0007/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24784","description":"The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-3107","versionConstraint":"<1.22.7||>=1.23.0-0,<1.23.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-3107","fix":{"state":"fixed","versions":["1.22.7","1.23.1"],"available":[{"date":"2024-09-05","kind":"release","version":"1.22.7"},{"date":"2024-09-05","kind":"release","version":"1.23.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34158","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34158","date":"2026-10-08","epss":0.01046,"percentile":0.63108}],"risk":0.7845000000000001,"urls":["https://go.dev/issue/69141","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/611240","description":"Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2024-34158","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34158","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34158","date":"2026-10-08","epss":0.01046,"percentile":0.63108}],"urls":["https://go.dev/cl/611240","https://go.dev/issue/69141","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk","https://pkg.go.dev/vuln/GO-2024-3107","https://security.netapp.com/advisory/ntap-20241004-0003/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34158","description":"Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1751","versionConstraint":"<1.19.9||>=1.20.0-0,<1.20.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1751","fix":{"state":"fixed","versions":["1.19.9","1.20.4"],"available":[{"date":"2023-05-02","kind":"release","version":"1.19.9"},{"date":"2023-05-02","kind":"release","version":"1.20.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24539","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24539","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24539","date":"2026-10-08","epss":0.01037,"percentile":0.62858}],"risk":0.7673800000000001,"urls":["https://go.dev/cl/491615","https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/59720","description":"Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input."},"relatedVulnerabilities":[{"id":"CVE-2023-24539","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24539","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-24539","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-24539","date":"2026-10-08","epss":0.01037,"percentile":0.62858}],"urls":["https://go.dev/cl/491615","https://go.dev/issue/59720","https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU","https://pkg.go.dev/vuln/GO-2023-1751","https://security.netapp.com/advisory/ntap-20241129-0005/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24539","description":"Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1753","versionConstraint":"<1.19.9||>=1.20.0-0,<1.20.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1753","fix":{"state":"fixed","versions":["1.19.9","1.20.4"],"available":[{"date":"2023-05-02","kind":"release","version":"1.19.9"},{"date":"2023-05-02","kind":"release","version":"1.20.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29400","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-29400","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-29400","date":"2026-10-08","epss":0.01037,"percentile":0.62858}],"risk":0.7673800000000001,"urls":["https://go.dev/cl/491617","https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/59722","description":"Templates containing actions in unquoted HTML attributes (e.g. \"attr={{.}}\") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags."},"relatedVulnerabilities":[{"id":"CVE-2023-29400","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29400","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-29400","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-29400","date":"2026-10-08","epss":0.01037,"percentile":0.62858}],"urls":["https://go.dev/cl/491617","https://go.dev/issue/59722","https://groups.google.com/g/golang-announce/c/MEb0UyuSMsU","https://pkg.go.dev/vuln/GO-2023-1753","https://security.netapp.com/advisory/ntap-20241213-0005/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29400","description":"Templates containing actions in unquoted HTML attributes (e.g. \"attr={{.}}\") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags."}]},{"artifact":{"id":"40beb4f8a2ae0009","cpes":["cpe:2.3:a:cryptography.io:cryptography:43.0.3:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:43.0.3:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@43.0.3","type":"python","version":"43.0.3","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"44.0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-79v4-65xg-pq4g","versionConstraint":">=42.0.0,<44.0.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"43.0.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-79v4-65xg-pq4g","fix":{"state":"fixed","versions":["44.0.1"],"available":[{"date":"2025-02-12","kind":"first-observed","version":"44.0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2024-12797","cwe":"CWE-392","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-12797","date":"2026-10-08","epss":0.02531,"percentile":0.8444}],"risk":0.7592999999999999,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-79v4-65xg-pq4g","https://openssl-library.org/news/secadv/20250211.txt","https://nvd.nist.gov/vuln/detail/CVE-2024-12797","https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9","https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7","https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699","http://www.openwall.com/lists/oss-security/2025/02/11/3","http://www.openwall.com/lists/oss-security/2025/02/11/4"],"severity":"Low","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-79v4-65xg-pq4g","description":"Vulnerable OpenSSL included in cryptography wheels"},"relatedVulnerabilities":[{"id":"CVE-2024-12797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12797","cwe":"CWE-392","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-12797","date":"2026-10-08","epss":0.02531,"percentile":0.8444}],"urls":["https://github.com/openssl/openssl/commit/738d4f9fdeaad57660dcba50a619fafced3fd5e9","https://github.com/openssl/openssl/commit/798779d43494549b611233f92652f0da5328fbe7","https://github.com/openssl/openssl/commit/87ebd203feffcf92ad5889df92f90bb0ee10a699","https://openssl-library.org/news/secadv/20250211.txt","http://www.openwall.com/lists/oss-security/2025/02/11/3","http://www.openwall.com/lists/oss-security/2025/02/11/4","https://security.netapp.com/advisory/ntap-20250214-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-12797","description":"Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a\nserver may fail to notice that the server was not authenticated, because\nhandshakes don't abort as expected when the SSL_VERIFY_PEER verification mode\nis set.\n\nImpact summary: TLS and DTLS connections using raw public keys may be\nvulnerable to man-in-middle attacks when server authentication failure is not\ndetected by clients.\n\nRPKs are disabled by default in both TLS clients and TLS servers.  The issue\nonly arises when TLS clients explicitly enable RPK use by the server, and the\nserver, likewise, enables sending of an RPK instead of an X.509 certificate\nchain.  The affected clients are those that then rely on the handshake to\nfail when the server's RPK fails to match one of the expected public keys,\nby setting the verification mode to SSL_VERIFY_PEER.\n\nClients that enable server-side raw public keys can still find out that raw\npublic key verification failed by calling SSL_get_verify_result(), and those\nthat do, and take appropriate action, are not affected.  This issue was\nintroduced in the initial implementation of RPK support in OpenSSL 3.2.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3563","versionConstraint":"<1.23.8||>=1.24.0-0,<1.24.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3563","fix":{"state":"fixed","versions":["1.23.8","1.24.2"],"available":[{"date":"2025-04-01","kind":"release","version":"1.23.8"},{"date":"2025-04-01","kind":"release","version":"1.24.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22871","date":"2026-10-08","epss":0.00811,"percentile":0.55659}],"risk":0.7339549999999999,"urls":["https://go.dev/issue/71988","https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/652998","description":"The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext."},"relatedVulnerabilities":[{"id":"CVE-2025-22871","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-22871","date":"2026-10-08","epss":0.00811,"percentile":0.55659}],"urls":["https://go.dev/cl/652998","https://go.dev/issue/71988","https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk","https://pkg.go.dev/vuln/GO-2025-3563","http://www.openwall.com/lists/oss-security/2025/04/04/4","https://cert-portal.siemens.com/productcert/html/ssa-783943.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22871","description":"The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2599","versionConstraint":"<1.21.8||>=1.22.0-0,<1.22.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2599","fix":{"state":"fixed","versions":["1.21.8","1.22.1"],"available":[{"date":"2024-03-05","kind":"release","version":"1.21.8"},{"date":"2024-03-05","kind":"release","version":"1.22.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45290","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-45290","date":"2026-10-08","epss":0.01165,"percentile":0.66334}],"risk":0.669875,"urls":["https://go.dev/cl/569341","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/65383","description":"When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion.\n\nWith fix, the ParseMultipartForm function now correctly limits the maximum size of form lines."},"relatedVulnerabilities":[{"id":"CVE-2023-45290","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45290","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-45290","date":"2026-10-08","epss":0.01165,"percentile":0.66334}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/08/4","https://go.dev/cl/569341","https://go.dev/issue/65383","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg","https://pkg.go.dev/vuln/GO-2024-2599","https://security.netapp.com/advisory/ntap-20240329-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45290","description":"When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines."}]},{"artifact":{"id":"ef1c469ce2c5e953","cpes":["cpe:2.3:a:pyopenssl_developers_project:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developers_project:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developersproject:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developersproject:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_dev_project:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_dev_project:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_devproject:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_devproject:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developers_project:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developers:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developers:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developersproject:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_dev_project:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography-dev:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography-dev:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_dev:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_dev:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_devproject:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python-pyopenssl:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python-pyopenssl:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python_pyopenssl:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python_pyopenssl:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl_developers:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography-dev:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cryptography_dev:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python-pyopenssl:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python_pyopenssl:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:pyopenssl:pyopenssl:24.2.1:*:*:*:*:*:*:*","cpe:2.3:a:python:pyopenssl:24.2.1:*:*:*:*:*:*:*"],"name":"pyopenssl","purl":"pkg:pypi/pyopenssl@24.2.1","type":"python","version":"24.2.1","language":"python","licenses":["Apache License, Version 2.0"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pyOpenSSL-24.2.1.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pyOpenSSL-24.2.1.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pyOpenSSL-24.2.1.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pyOpenSSL-24.2.1.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/lsiopy/lib/python3.12/site-packages/pyOpenSSL-24.2.1.dist-info/top_level.txt","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pyOpenSSL-24.2.1.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"26.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5pwr-322w-8jr4","versionConstraint":">=22.0.0,<26.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pyopenssl","version":"24.2.1"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-5pwr-322w-8jr4","fix":{"state":"fixed","versions":["26.0.0"],"available":[{"date":"2026-03-16","kind":"first-observed","version":"26.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27459","cwe":"CWE-120","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27459","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27459","date":"2026-10-08","epss":0.00882,"percentile":0.5791}],"risk":0.64827,"urls":["https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4","https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408","https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst","https://nvd.nist.gov/vuln/detail/CVE-2026-27459"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5pwr-322w-8jr4","description":"pyOpenSSL DTLS cookie callback buffer overflow"},"relatedVulnerabilities":[{"id":"CVE-2026-27459","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27459","cwe":"CWE-120","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27459","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27459","date":"2026-10-08","epss":0.00882,"percentile":0.5791}],"urls":["https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst","https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408","https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4","https://access.redhat.com/errata/RHSA-2026:10754","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13553","https://access.redhat.com/errata/RHSA-2026:14835","https://access.redhat.com/errata/RHSA-2026:14873","https://access.redhat.com/errata/RHSA-2026:14874","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:48085","https://access.redhat.com/errata/RHSA-2026:48758","https://access.redhat.com/errata/RHSA-2026:59153","https://access.redhat.com/errata/RHSA-2026:7224","https://access.redhat.com/errata/RHSA-2026:8437","https://access.redhat.com/security/cve/CVE-2026-27459","https://bugzilla.redhat.com/show_bug.cgi?id=2448503","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27459","description":"pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-1095","versionConstraint":"<1.18.8||>=1.19.0-0,<1.19.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-1095","fix":{"state":"fixed","versions":["1.18.8","1.19.3"],"available":[{"date":"2022-11-01","kind":"release","version":"1.18.8"},{"date":"2022-11-01","kind":"release","version":"1.19.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41716","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41716","date":"2026-10-08","epss":0.00853,"percentile":0.57}],"risk":0.6397499999999999,"urls":["https://go.dev/cl/446916","https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/56284","description":"Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows.\n\nIn syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string \"A=B\\x00C=D\" sets the variables \"A=B\" and \"C=D\"."},"relatedVulnerabilities":[{"id":"CVE-2022-41716","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41716","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41716","date":"2026-10-08","epss":0.00853,"percentile":0.57}],"urls":["https://go.dev/cl/446916","https://go.dev/issue/56284","https://groups.google.com/g/golang-announce/c/mbHY1UY3BaM/m/hSpmRzk-AgAJ","https://pkg.go.dev/vuln/GO-2022-1095","https://security.netapp.com/advisory/ntap-20230120-0007/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41716","description":"Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string \"A=B\\x00C=D\" sets the variables \"A=B\" and \"C=D\"."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4601","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4601","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"risk":0.6255000000000001,"urls":["https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/752180","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-25679","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"urls":["https://go.dev/cl/752180","https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4601","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10133","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10169","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:10701","https://access.redhat.com/errata/RHSA-2026:10712","https://access.redhat.com/errata/RHSA-2026:10929","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11375","https://access.redhat.com/errata/RHSA-2026:11412","https://access.redhat.com/errata/RHSA-2026:11413","https://access.redhat.com/errata/RHSA-2026:11686","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:11800","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13642","https://access.redhat.com/errata/RHSA-2026:13643","https://access.redhat.com/errata/RHSA-2026:13671","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19022","https://access.redhat.com/errata/RHSA-2026:19026","https://access.redhat.com/errata/RHSA-2026:19027","https://access.redhat.com/errata/RHSA-2026:19031","https://access.redhat.com/errata/RHSA-2026:19032","https://access.redhat.com/errata/RHSA-2026:19049","https://access.redhat.com/errata/RHSA-2026:19055","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19128","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19181","https://access.redhat.com/errata/RHSA-2026:19184","https://access.redhat.com/errata/RHSA-2026:19185","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19475","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20581","https://access.redhat.com/errata/RHSA-2026:20582","https://access.redhat.com/errata/RHSA-2026:20584","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22733","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24386","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:25043","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26445","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52389","https://access.redhat.com/errata/RHSA-2026:52390","https://access.redhat.com/errata/RHSA-2026:52391","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:5941","https://access.redhat.com/errata/RHSA-2026:5942","https://access.redhat.com/errata/RHSA-2026:5943","https://access.redhat.com/errata/RHSA-2026:5944","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:6341","https://access.redhat.com/errata/RHSA-2026:6344","https://access.redhat.com/errata/RHSA-2026:6382","https://access.redhat.com/errata/RHSA-2026:6383","https://access.redhat.com/errata/RHSA-2026:6388","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:6720","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:6949","https://access.redhat.com/errata/RHSA-2026:7005","https://access.redhat.com/errata/RHSA-2026:7009","https://access.redhat.com/errata/RHSA-2026:7011","https://access.redhat.com/errata/RHSA-2026:7259","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7315","https://access.redhat.com/errata/RHSA-2026:7328","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7665","https://access.redhat.com/errata/RHSA-2026:7669","https://access.redhat.com/errata/RHSA-2026:7674","https://access.redhat.com/errata/RHSA-2026:7833","https://access.redhat.com/errata/RHSA-2026:7834","https://access.redhat.com/errata/RHSA-2026:7876","https://access.redhat.com/errata/RHSA-2026:7877","https://access.redhat.com/errata/RHSA-2026:7878","https://access.redhat.com/errata/RHSA-2026:7879","https://access.redhat.com/errata/RHSA-2026:7883","https://access.redhat.com/errata/RHSA-2026:7992","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8314","https://access.redhat.com/errata/RHSA-2026:8322","https://access.redhat.com/errata/RHSA-2026:8324","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8434","https://access.redhat.com/errata/RHSA-2026:8456","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:8840","https://access.redhat.com/errata/RHSA-2026:8841","https://access.redhat.com/errata/RHSA-2026:8842","https://access.redhat.com/errata/RHSA-2026:8845","https://access.redhat.com/errata/RHSA-2026:8847","https://access.redhat.com/errata/RHSA-2026:8848","https://access.redhat.com/errata/RHSA-2026:8849","https://access.redhat.com/errata/RHSA-2026:8851","https://access.redhat.com/errata/RHSA-2026:8852","https://access.redhat.com/errata/RHSA-2026:8853","https://access.redhat.com/errata/RHSA-2026:8855","https://access.redhat.com/errata/RHSA-2026:8856","https://access.redhat.com/errata/RHSA-2026:8860","https://access.redhat.com/errata/RHSA-2026:8877","https://access.redhat.com/errata/RHSA-2026:8878","https://access.redhat.com/errata/RHSA-2026:8879","https://access.redhat.com/errata/RHSA-2026:8881","https://access.redhat.com/errata/RHSA-2026:8882","https://access.redhat.com/errata/RHSA-2026:8930","https://access.redhat.com/errata/RHSA-2026:8931","https://access.redhat.com/errata/RHSA-2026:8949","https://access.redhat.com/errata/RHSA-2026:9043","https://access.redhat.com/errata/RHSA-2026:9044","https://access.redhat.com/errata/RHSA-2026:9052","https://access.redhat.com/errata/RHSA-2026:9090","https://access.redhat.com/errata/RHSA-2026:9093","https://access.redhat.com/errata/RHSA-2026:9094","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9434","https://access.redhat.com/errata/RHSA-2026:9435","https://access.redhat.com/errata/RHSA-2026:9436","https://access.redhat.com/errata/RHSA-2026:9439","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9461","https://access.redhat.com/errata/RHSA-2026:9695","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-25679","https://bugzilla.redhat.com/show_bug.cgi?id=2445356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25679","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.20.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-2382","versionConstraint":"<1.20.12||>=1.21.0-0,<1.21.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-2382","fix":{"state":"fixed","versions":["1.20.12","1.21.5"],"available":[{"date":"2023-12-05","kind":"release","version":"1.20.12"},{"date":"2023-12-05","kind":"release","version":"1.21.5"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39326","date":"2026-10-08","epss":0.01208,"percentile":0.67458}],"risk":0.62212,"urls":["https://go.dev/cl/547335","https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/64433","description":"A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body.\n\nA malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request.\n\nChunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small."},"relatedVulnerabilities":[{"id":"CVE-2023-39326","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-39326","date":"2026-10-08","epss":0.01208,"percentile":0.67458}],"urls":["https://go.dev/cl/547335","https://go.dev/issue/64433","https://groups.google.com/g/golang-dev/c/6ypN5EjibjM/m/KmLVYH_uAgAJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UIU6HOGV6RRIKWM57LOXQA75BGZSIH6G/","https://pkg.go.dev/vuln/GO-2023-2382"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39326","description":"A malicious HTTP sender can use chunk extensions to cause a receiver reading from a request or response body to read many more bytes from the network than are in the body. A malicious HTTP client can further exploit this to cause a server to automatically read a large amount of data (up to about 1GiB) when a handler fails to read the entire body of a request. Chunk extensions are a little-used HTTP feature which permit including additional metadata in a request or response body sent using the chunked encoding. The net/http chunked encoding reader discards this metadata. A sender can exploit this by inserting a large metadata segment with each byte transferred. The chunk reader now produces an error if the ratio of real body to encoded bytes grows too small."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4981","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4981","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"risk":0.60975,"urls":["https://go.dev/cl/767860","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78803","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-33811","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"urls":["https://go.dev/cl/767860","https://go.dev/issue/78803","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4981","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:35995","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36617","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36776","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:39266","https://access.redhat.com/errata/RHSA-2026:39272","https://access.redhat.com/errata/RHSA-2026:39319","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54556","https://access.redhat.com/errata/RHSA-2026:54584","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56790","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60302","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61313","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/security/cve/CVE-2026-33811","https://bugzilla.redhat.com/show_bug.cgi?id=2467822","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4977","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4977","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"risk":0.5984999999999999,"urls":["https://go.dev/cl/771520","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78987","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."},"relatedVulnerabilities":[{"id":"CVE-2026-42499","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"urls":["https://go.dev/cl/771520","https://go.dev/issue/78987","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4977","https://access.redhat.com/errata/RHSA-2026:17713","https://access.redhat.com/errata/RHSA-2026:17714","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:63163","https://access.redhat.com/errata/RHSA-2026:63332","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:64818","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67148","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-42499","https://bugzilla.redhat.com/show_bug.cgi?id=2467809","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42499","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4986","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4986","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"risk":0.588,"urls":["https://go.dev/cl/759940","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78566","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-39820","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"urls":["https://go.dev/cl/759940","https://go.dev/issue/78566","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4986","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54883","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57401","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-39820","https://bugzilla.redhat.com/show_bug.cgi?id=2467820","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"a9c1f2bbf70f37c8","cpes":["cpe:2.3:a:libjpeg-turbo8:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg-turbo8:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*"],"name":"libjpeg-turbo8","purl":"pkg:deb/ubuntu/libjpeg-turbo8@2.1.5-2ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=libjpeg-turbo","type":"deb","version":"2.1.5-2ubuntu2","language":"","licenses":["BSD-3-clause","BSD-BY-LC-NE","Expat","NTP","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjpeg-turbo8/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libjpeg-turbo8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libjpeg-turbo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-10126","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libjpeg-turbo","version":"2.1.5-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2018-10126","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10126","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"risk":0.5487,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-10126"},"relatedVulnerabilities":[{"id":"CVE-2018-10126","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10126","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2786","https://gitlab.com/libtiff/libtiff/-/issues/128","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10126","description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"57ae2119a8593e71","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/ubuntu/libopenjp2-7@2.5.0-2ubuntu0.5?arch=amd64&distro=ubuntu-24.04&upstream=openjpeg2","type":"deb","version":"2.5.0-2ubuntu0.5","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openjpeg2","version":"2.5.0-2ubuntu0.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2019-6988","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"risk":0.5172,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-6988"},"relatedVulnerabilities":[{"id":"CVE-2019-6988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.20.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-2041","versionConstraint":"<1.20.8||>=1.21.0-0,<1.21.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-2041","fix":{"state":"fixed","versions":["1.20.8","1.21.1"],"available":[{"date":"2023-09-06","kind":"release","version":"1.20.8"},{"date":"2023-09-06","kind":"release","version":"1.21.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39318","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39318","date":"2026-10-08","epss":0.0093,"percentile":0.59397}],"risk":0.5161499999999999,"urls":["https://go.dev/cl/526156","https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/62196","description":"The html/template package does not properly handle HTML-like \"\" comment tokens, nor hashbang \"#!\" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack."},"relatedVulnerabilities":[{"id":"CVE-2023-39318","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39318","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39318","date":"2026-10-08","epss":0.0093,"percentile":0.59397}],"urls":["https://go.dev/cl/526156","https://go.dev/issue/62196","https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ","https://pkg.go.dev/vuln/GO-2023-2041","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20231020-0009/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39318","description":"The html/template package does not properly handle HTML-like \"\" comment tokens, nor hashbang \"#!\" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.20.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-2043","versionConstraint":"<1.20.8||>=1.21.0-0,<1.21.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-2043","fix":{"state":"fixed","versions":["1.20.8","1.21.1"],"available":[{"date":"2023-09-06","kind":"release","version":"1.20.8"},{"date":"2023-09-06","kind":"release","version":"1.21.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39319","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39319","date":"2026-10-08","epss":0.00911,"percentile":0.58777}],"risk":0.505605,"urls":["https://go.dev/cl/526157","https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/62197","description":"The html/template package does not apply the proper rules for handling occurrences of \"<script\", \"<!--\", and \"</script\" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack."},"relatedVulnerabilities":[{"id":"CVE-2023-39319","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39319","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-39319","date":"2026-10-08","epss":0.00911,"percentile":0.58777}],"urls":["https://go.dev/cl/526157","https://go.dev/issue/62197","https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ","https://pkg.go.dev/vuln/GO-2023-2043","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20231020-0009/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39319","description":"The html/template package does not apply the proper rules for handling occurrences of \"<script\", \"<!--\", and \"</script\" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.14.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g867-7843-wf8q","versionConstraint":"<6.14.2 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-g867-7843-wf8q","fix":{"state":"fixed","versions":["6.14.2"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"6.14.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59935","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59935","date":"2026-10-08","epss":0.0062,"percentile":0.48081}],"risk":0.5022,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-g867-7843-wf8q","https://nvd.nist.gov/vuln/detail/CVE-2026-59935","https://github.com/py-pdf/pypdf/pull/3892","https://github.com/py-pdf/pypdf/commit/5a33a46416aa1ae6c025ff90a3cca57631fdafd2","https://github.com/py-pdf/pypdf/releases/tag/6.14.2"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g867-7843-wf8q","description":"pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)"},"relatedVulnerabilities":[{"id":"CVE-2026-59935","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59935","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59935","date":"2026-10-08","epss":0.0062,"percentile":0.48081}],"urls":["https://github.com/py-pdf/pypdf/commit/5a33a46416aa1ae6c025ff90a3cca57631fdafd2","https://github.com/py-pdf/pypdf/pull/3892","https://github.com/py-pdf/pypdf/releases/tag/6.14.2","https://github.com/py-pdf/pypdf/security/advisories/GHSA-g867-7843-wf8q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59935","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not terminated inline image that uses the ASCII85 or ASCIIHex filters, causing an infinite loop during parsing such as when extracting page text. This issue is fixed in version 6.14.2."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.14.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5xf7-4p34-54qr","versionConstraint":"<6.14.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-5xf7-4p34-54qr","fix":{"state":"fixed","versions":["6.14.1"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"6.14.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59936","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59936","date":"2026-10-08","epss":0.0062,"percentile":0.4808}],"risk":0.5022,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-5xf7-4p34-54qr","https://nvd.nist.gov/vuln/detail/CVE-2026-59936","https://github.com/py-pdf/pypdf/pull/3891","https://github.com/py-pdf/pypdf/commit/ec3b14596186c40caca7cf8ab9b2155203e01b5b","https://github.com/py-pdf/pypdf/releases/tag/6.14.1"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5xf7-4p34-54qr","description":"pypdf: Possible infinite loop for not terminated inline images"},"relatedVulnerabilities":[{"id":"CVE-2026-59936","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59936","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59936","date":"2026-10-08","epss":0.0062,"percentile":0.4808}],"urls":["https://github.com/py-pdf/pypdf/commit/ec3b14596186c40caca7cf8ab9b2155203e01b5b","https://github.com/py-pdf/pypdf/pull/3891","https://github.com/py-pdf/pypdf/releases/tag/6.14.1","https://github.com/py-pdf/pypdf/security/advisories/GHSA-5xf7-4p34-54qr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59936","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not terminated inline image, causing an infinite loop during inline image end marker detection such as when extracting page text. This issue is fixed in version 6.14.1."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2600","versionConstraint":"<1.21.8||>=1.22.0-0,<1.22.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2600","fix":{"state":"fixed","versions":["1.21.8","1.22.1"],"available":[{"date":"2024-03-05","kind":"release","version":"1.21.8"},{"date":"2024-03-05","kind":"release","version":"1.22.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45289","date":"2026-10-08","epss":0.0108,"percentile":0.64084}],"risk":0.5022,"urls":["https://go.dev/cl/569340","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/65065","description":"When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as \"Authorization\" or \"Cookie\". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not.\n\nA maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded."},"relatedVulnerabilities":[{"id":"CVE-2023-45289","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45289","date":"2026-10-08","epss":0.0108,"percentile":0.64084}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/08/4","https://go.dev/cl/569340","https://go.dev/issue/65065","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg","https://pkg.go.dev/vuln/GO-2024-2600","https://security.netapp.com/advisory/ntap-20240329-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45289","description":"When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as \"Authorization\" or \"Cookie\". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4009","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4009","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"risk":0.49575,"urls":["https://go.dev/cl/709858","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75676","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input.\n\nThis affects programs which parse untrusted PEM inputs."},"relatedVulnerabilities":[{"id":"CVE-2025-61723","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61723","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61723","date":"2026-10-08","epss":0.00661,"percentile":0.50098}],"urls":["https://go.dev/cl/709858","https://go.dev/issue/75676","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4009","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61723","description":"The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4006","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4006","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"risk":0.48525,"urls":["https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709860","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61725","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61725","date":"2026-10-08","epss":0.00647,"percentile":0.49441}],"urls":["https://go.dev/cl/709860","https://go.dev/issue/75680","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4006","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61725","description":"The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0515","versionConstraint":"<1.17.12||>=1.18.0-0,<1.18.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0515","fix":{"state":"fixed","versions":["1.17.12","1.18.4"],"available":[{"date":"2022-07-12","kind":"release","version":"1.17.12"},{"date":"2022-07-12","kind":"release","version":"1.18.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1962","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1962","date":"2026-10-08","epss":0.00916,"percentile":0.58983}],"risk":0.4809,"urls":["https://go.googlesource.com/go/+/695be961d57508da5a82217f7415200a11845879","https://go.dev/issue/53616","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/417063","description":"Calling any of the Parse functions on Go source code which contains deeply nested types or declarations can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2022-1962","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-1962","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-1962","date":"2026-10-08","epss":0.00916,"percentile":0.58983}],"urls":["https://go.dev/cl/417063","https://go.dev/issue/53616","https://go.googlesource.com/go/+/695be961d57508da5a82217f7415200a11845879","https://groups.google.com/g/golang-announce/c/nqrv9fbR0zE","https://pkg.go.dev/vuln/GO-2022-0515"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-1962","description":"Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-55154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55154","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"risk":0.48050000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55154"},"relatedVulnerabilities":[{"id":"CVE-2025-55154","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp29-wxp5-wh82","https://goo.gle/bigsleep","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55154","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55154","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"risk":0.48050000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55154"},"relatedVulnerabilities":[{"id":"CVE-2025-55154","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp29-wxp5-wh82","https://goo.gle/bigsleep","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55154","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55154","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"risk":0.48050000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55154"},"relatedVulnerabilities":[{"id":"CVE-2025-55154","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp29-wxp5-wh82","https://goo.gle/bigsleep","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55154","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55154","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"risk":0.48050000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55154"},"relatedVulnerabilities":[{"id":"CVE-2025-55154","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp29-wxp5-wh82","https://goo.gle/bigsleep","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55154","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55154","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"risk":0.48050000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55154"},"relatedVulnerabilities":[{"id":"CVE-2025-55154","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55154","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55154","date":"2026-10-08","epss":0.00961,"percentile":0.60435}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qp29-wxp5-wh82","https://goo.gle/bigsleep","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55154","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (in coders/png.c) are unsafe and can overflow, leading to memory corruption. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0532","versionConstraint":"<1.17.11||>=1.18.0-0,<1.18.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0532","fix":{"state":"fixed","versions":["1.17.11","1.18.3"],"available":[{"date":"2022-06-01","kind":"release","version":"1.17.11"},{"date":"2022-06-01","kind":"release","version":"1.18.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30580","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-30580","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-30580","date":"2026-10-08","epss":0.00627,"percentile":0.48443}],"risk":0.479655,"urls":["https://go.googlesource.com/go/+/960ffa98ce73ef2c2060c84c7ac28d37a83f345e","https://go.dev/issue/52574","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/403759","description":"On Windows, executing Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset will unintentionally trigger execution of any binaries in the working directory named either \"..com\" or \"..exe\"."},"relatedVulnerabilities":[{"id":"CVE-2022-30580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30580","cwe":"CWE-94","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-30580","cwe":"CWE-94","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-30580","date":"2026-10-08","epss":0.00627,"percentile":0.48443}],"urls":["https://go.dev/cl/403759","https://go.dev/issue/52574","https://go.googlesource.com/go/+/960ffa98ce73ef2c2060c84c7ac28d37a83f345e","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ","https://pkg.go.dev/vuln/GO-2022-0532"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30580","description":"Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either \"..com\" or \"..exe\" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4870","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4870","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"risk":0.46575,"urls":["https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763767","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.\n\nThis only affects TLS 1.3."},"relatedVulnerabilities":[{"id":"CVE-2026-32283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"urls":["https://go.dev/cl/763767","https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4870","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11704","https://access.redhat.com/errata/RHSA-2026:11711","https://access.redhat.com/errata/RHSA-2026:11712","https://access.redhat.com/errata/RHSA-2026:11863","https://access.redhat.com/errata/RHSA-2026:11881","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17075","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19134","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19136","https://access.redhat.com/errata/RHSA-2026:19137","https://access.redhat.com/errata/RHSA-2026:19139","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19156","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19351","https://access.redhat.com/errata/RHSA-2026:19352","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19369","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55898","https://access.redhat.com/errata/RHSA-2026:55900","https://access.redhat.com/errata/RHSA-2026:55901","https://access.redhat.com/errata/RHSA-2026:55902","https://access.redhat.com/errata/RHSA-2026:55903","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:57802","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65343","https://access.redhat.com/errata/RHSA-2026:65514","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66084","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:66523","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/security/cve/CVE-2026-32283","https://bugzilla.redhat.com/show_bug.cgi?id=2456338","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32283","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.20.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-2186","versionConstraint":"<1.20.11||>=1.21.0-0,<1.21.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-2186","fix":{"state":"fixed","versions":["1.20.11","1.21.4"],"available":[{"date":"2023-11-07","kind":"release","version":"1.20.11"},{"date":"2023-11-07","kind":"release","version":"1.21.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45284","date":"2026-10-08","epss":0.00903,"percentile":0.58534}],"risk":0.46504500000000004,"urls":["https://go.dev/cl/540277","https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/63713","description":"On Windows, The IsLocal function does not correctly detect reserved device names in some cases.\n\nReserved names followed by spaces, such as \"COM1 \", and reserved names \"COM\" and \"LPT\" followed by superscript 1, 2, or 3, are incorrectly reported as local.\n\nWith fix, IsLocal now correctly reports these names as non-local."},"relatedVulnerabilities":[{"id":"CVE-2023-45284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-45284","date":"2026-10-08","epss":0.00903,"percentile":0.58534}],"urls":["https://go.dev/cl/540277","https://go.dev/issue/63713","https://groups.google.com/g/golang-announce/c/4tU8LZfBFkY","https://pkg.go.dev/vuln/GO-2023-2186"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45284","description":"On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as \"COM1 \", and reserved names \"COM\" and \"LPT\" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4971","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4971","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"risk":0.46499999999999997,"urls":["https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://go.dev/cl/775320"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79006","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."},"relatedVulnerabilities":[{"id":"CVE-2026-39836","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"urls":["https://go.dev/cl/775320","https://go.dev/issue/79006","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4971"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4947","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4947","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"risk":0.46125000000000005,"urls":["https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758320","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},"relatedVulnerabilities":[{"id":"CVE-2026-32280","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"urls":["https://go.dev/cl/758320","https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4947","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16476","https://access.redhat.com/errata/RHSA-2026:16477","https://access.redhat.com/errata/RHSA-2026:16505","https://access.redhat.com/errata/RHSA-2026:16508","https://access.redhat.com/errata/RHSA-2026:16532","https://access.redhat.com/errata/RHSA-2026:16534","https://access.redhat.com/errata/RHSA-2026:16535","https://access.redhat.com/errata/RHSA-2026:16537","https://access.redhat.com/errata/RHSA-2026:16542","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21338","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:22130","https://access.redhat.com/errata/RHSA-2026:22141","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22268","https://access.redhat.com/errata/RHSA-2026:22309","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22415","https://access.redhat.com/errata/RHSA-2026:22422","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22958","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22960","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:22962","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23244","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24359","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24478","https://access.redhat.com/errata/RHSA-2026:24716","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:28196","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:39894","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49526","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49838","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:59834","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61685","https://access.redhat.com/errata/RHSA-2026:61906","https://access.redhat.com/errata/RHSA-2026:61907","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/security/cve/CVE-2026-32280","https://bugzilla.redhat.com/show_bug.cgi?id=2456339","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32280","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-53101","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53101","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"risk":0.457,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53101"},"relatedVulnerabilities":[{"id":"CVE-2025-53101","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh3h-j545-h8c9","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53101","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53101","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53101","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"risk":0.457,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53101"},"relatedVulnerabilities":[{"id":"CVE-2025-53101","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh3h-j545-h8c9","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53101","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53101","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53101","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"risk":0.457,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53101"},"relatedVulnerabilities":[{"id":"CVE-2025-53101","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh3h-j545-h8c9","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53101","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53101","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53101","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"risk":0.457,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53101"},"relatedVulnerabilities":[{"id":"CVE-2025-53101","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh3h-j545-h8c9","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53101","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53101","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53101","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"risk":0.457,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53101"},"relatedVulnerabilities":[{"id":"CVE-2025-53101","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53101","cwe":"CWE-124","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53101","date":"2026-10-08","epss":0.00914,"percentile":0.58891}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh3h-j545-h8c9","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53101","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-55212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55212","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"risk":0.45599999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55212"},"relatedVulnerabilities":[{"id":"CVE-2025-55212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"urls":["https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/geometry.c#L355","https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/resize.c#L4625-L4629","https://github.com/ImageMagick/ImageMagick/commit/5f0bcf986b8b5e90567750d31a37af502b73f2af","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fh55-q5pj-pxgw","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55212","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (\":\") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in a denial of service. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55212","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"risk":0.45599999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55212"},"relatedVulnerabilities":[{"id":"CVE-2025-55212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"urls":["https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/geometry.c#L355","https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/resize.c#L4625-L4629","https://github.com/ImageMagick/ImageMagick/commit/5f0bcf986b8b5e90567750d31a37af502b73f2af","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fh55-q5pj-pxgw","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55212","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (\":\") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in a denial of service. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55212","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"risk":0.45599999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55212"},"relatedVulnerabilities":[{"id":"CVE-2025-55212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"urls":["https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/geometry.c#L355","https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/resize.c#L4625-L4629","https://github.com/ImageMagick/ImageMagick/commit/5f0bcf986b8b5e90567750d31a37af502b73f2af","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fh55-q5pj-pxgw","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55212","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (\":\") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in a denial of service. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55212","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"risk":0.45599999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55212"},"relatedVulnerabilities":[{"id":"CVE-2025-55212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"urls":["https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/geometry.c#L355","https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/resize.c#L4625-L4629","https://github.com/ImageMagick/ImageMagick/commit/5f0bcf986b8b5e90567750d31a37af502b73f2af","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fh55-q5pj-pxgw","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55212","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (\":\") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in a denial of service. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55212","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55212","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"risk":0.45599999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55212"},"relatedVulnerabilities":[{"id":"CVE-2025-55212","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55212","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55212","date":"2026-10-08","epss":0.00912,"percentile":0.58801}],"urls":["https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/geometry.c#L355","https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/resize.c#L4625-L4629","https://github.com/ImageMagick/ImageMagick/commit/5f0bcf986b8b5e90567750d31a37af502b73f2af","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fh55-q5pj-pxgw","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55212","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (\":\") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in a denial of service. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44432","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44432","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44432","date":"2026-10-08","epss":0.00882,"percentile":0.57906}],"risk":0.441,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44432"},"relatedVulnerabilities":[{"id":"CVE-2026-44432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44432","date":"2026-10-08","epss":0.00882,"percentile":0.57906}],"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j","https://access.redhat.com/errata/RHSA-2026:15862","https://access.redhat.com/errata/RHSA-2026:20338","https://access.redhat.com/errata/RHSA-2026:22934","https://access.redhat.com/errata/RHSA-2026:24000","https://access.redhat.com/errata/RHSA-2026:24009","https://access.redhat.com/errata/RHSA-2026:24014","https://access.redhat.com/errata/RHSA-2026:24069","https://access.redhat.com/errata/RHSA-2026:24374","https://access.redhat.com/errata/RHSA-2026:24476","https://access.redhat.com/errata/RHSA-2026:24483","https://access.redhat.com/errata/RHSA-2026:24540","https://access.redhat.com/errata/RHSA-2026:24541","https://access.redhat.com/errata/RHSA-2026:24542","https://access.redhat.com/errata/RHSA-2026:24544","https://access.redhat.com/errata/RHSA-2026:25039","https://access.redhat.com/errata/RHSA-2026:25143","https://access.redhat.com/errata/RHSA-2026:25928","https://access.redhat.com/errata/RHSA-2026:26212","https://access.redhat.com/errata/RHSA-2026:26304","https://access.redhat.com/errata/RHSA-2026:27929","https://access.redhat.com/errata/RHSA-2026:28000","https://access.redhat.com/errata/RHSA-2026:28157","https://access.redhat.com/errata/RHSA-2026:28158","https://access.redhat.com/errata/RHSA-2026:28159","https://access.redhat.com/errata/RHSA-2026:28571","https://access.redhat.com/errata/RHSA-2026:30076","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:32992","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:33683","https://access.redhat.com/errata/RHSA-2026:34160","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:34526","https://access.redhat.com/errata/RHSA-2026:34531","https://access.redhat.com/errata/RHSA-2026:34533","https://access.redhat.com/errata/RHSA-2026:34607","https://access.redhat.com/errata/RHSA-2026:36350","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42144","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:51206","https://access.redhat.com/errata/RHSA-2026:56347","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59409","https://access.redhat.com/errata/RHSA-2026:60362","https://access.redhat.com/errata/RHSA-2026:60371","https://access.redhat.com/errata/RHSA-2026:7625","https://access.redhat.com/errata/RHSA-2026:7634","https://access.redhat.com/security/cve/CVE-2026-44432","https://bugzilla.redhat.com/show_bug.cgi?id=2477154","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432","description":"urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0."}]},{"artifact":{"id":"04c8394872bf12a6","cpes":["cpe:2.3:a:py7zr_project:py7zr:0.20.8:*:*:*:*:python:*:*"],"name":"py7zr","purl":"pkg:pypi/py7zr@0.20.8","type":"python","version":"0.20.8","language":"python","licenses":["LGPL-2.1-or-later"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/py7zr-0.20.8.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/py7zr-0.20.8.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/py7zr-0.20.8.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/py7zr-0.20.8.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/lsiopy/lib/python3.12/site-packages/py7zr-0.20.8.dist-info/top_level.txt","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/py7zr-0.20.8.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.1.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q6rc-2cgv-63h7","versionConstraint":"<=1.1.2 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"py7zr","version":"0.20.8"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-q6rc-2cgv-63h7","fix":{"state":"fixed","versions":["1.1.3"],"available":[{"date":"2026-06-20","kind":"first-observed","version":"1.1.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23879","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23879","date":"2026-10-08","epss":0.00566,"percentile":0.4522}],"risk":0.43865,"urls":["https://github.com/miurahr/py7zr/security/advisories/GHSA-q6rc-2cgv-63h7","https://github.com/miurahr/py7zr/releases/tag/v1.1.3","https://nvd.nist.gov/vuln/detail/CVE-2026-23879","https://github.com/miurahr/py7zr","https://github.com/pypa/advisory-database/tree/main/vulns/py7zr/PYSEC-2026-2974.yaml","https://pypi.org/project/py7zr"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q6rc-2cgv-63h7","description":"py7zr: Arbitrary File Write Vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2026-23879","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23879","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23879","date":"2026-10-08","epss":0.00566,"percentile":0.4522}],"urls":["https://github.com/miurahr/py7zr/releases/tag/v1.1.3","https://github.com/miurahr/py7zr/security/advisories/GHSA-q6rc-2cgv-63h7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23879","description":"py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using extractall to extract an archive, the library restores these symbolic links, linking them to arbitrary directories on the host file system. During extraction, the program only checks the link arcname within the destination directory, but ignores the combined symlink path resolution. Attackers can exploit this vulnerability by constructing malicious archives, thereby bypassing the directory boundary restrictions implemented by the extractor. Subsequent extraction of regular files through these symbolic links can result in arbitrary file writes. This vulnerability may lead to remote code execution, privilege escalation, data corruption, or denial of service. This issue has been fixed in version 1.1.3."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4342","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4342","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"risk":0.430675,"urls":["https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736713","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."},"relatedVulnerabilities":[{"id":"CVE-2025-61728","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"urls":["https://go.dev/cl/736713","https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4342","http://www.openwall.com/lists/oss-security/2026/01/15/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61728","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-57803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-57803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"risk":0.4215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-57803"},"relatedVulnerabilities":[{"id":"CVE-2025-57803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmm","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-57803","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-57803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-57803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"risk":0.4215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-57803"},"relatedVulnerabilities":[{"id":"CVE-2025-57803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmm","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-57803","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-57803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-57803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"risk":0.4215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-57803"},"relatedVulnerabilities":[{"id":"CVE-2025-57803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmm","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-57803","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-57803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-57803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"risk":0.4215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-57803"},"relatedVulnerabilities":[{"id":"CVE-2025-57803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmm","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-57803","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-57803","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-57803","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"risk":0.4215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-57803"},"relatedVulnerabilities":[{"id":"CVE-2025-57803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-57803","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-57803","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-57803","date":"2026-10-08","epss":0.00843,"percentile":0.56654}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmm","https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-57803","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1621","versionConstraint":"<1.19.7||>=1.20.0-0,<1.20.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1621","fix":{"state":"fixed","versions":["1.19.7","1.20.2"],"available":[{"date":"2023-03-07","kind":"release","version":"1.19.7"},{"date":"2023-03-07","kind":"release","version":"1.20.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24532","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-24532","date":"2026-10-08","epss":0.00817,"percentile":0.55815}],"risk":0.420755,"urls":["https://go.dev/cl/471255","https://groups.google.com/g/golang-announce/c/3-TpUx48iQY"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/58647","description":"The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve).\n\nThis does not impact usages of crypto/ecdsa or crypto/ecdh."},"relatedVulnerabilities":[{"id":"CVE-2023-24532","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-24532","cwe":"CWE-682","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-24532","date":"2026-10-08","epss":0.00817,"percentile":0.55815}],"urls":["https://go.dev/cl/471255","https://go.dev/issue/58647","https://groups.google.com/g/golang-announce/c/3-TpUx48iQY","https://pkg.go.dev/vuln/GO-2023-1621","https://security.netapp.com/advisory/ntap-20230331-0011/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-24532","description":"The ScalarMult and ScalarBaseMult methods of the P256 Curve may return an incorrect result if called with some specific unreduced scalars (a scalar larger than the order of the curve). This does not impact usages of crypto/ecdsa or crypto/ecdh."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2610","versionConstraint":"<1.21.8||>=1.22.0-0,<1.22.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2610","fix":{"state":"fixed","versions":["1.21.8","1.22.1"],"available":[{"date":"2024-03-05","kind":"release","version":"1.21.8"},{"date":"2024-03-05","kind":"release","version":"1.22.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24785","date":"2026-10-08","epss":0.00795,"percentile":0.55095}],"risk":0.41340000000000005,"urls":["https://go.dev/cl/564196","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/65697","description":"If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates."},"relatedVulnerabilities":[{"id":"CVE-2024-24785","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24785","date":"2026-10-08","epss":0.00795,"percentile":0.55095}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/08/4","https://go.dev/cl/564196","https://go.dev/issue/65697","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg","https://pkg.go.dev/vuln/GO-2024-2610","https://security.netapp.com/advisory/ntap-20240329-0008/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24785","description":"If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-62171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-62171","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"risk":0.40449999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-62171"},"relatedVulnerabilities":[{"id":"CVE-2025-62171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cea1693e2ded51b4cc91c70c54096cbed1691c00","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9pp9-cfwx-54rm","https://lists.debian.org/debian-lts-announce/2025/10/msg00019.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-62171","description":"ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vulnerability only affects 32-bit builds of ImageMagick where default resource limits for width, height, and area have been manually increased beyond their defaults. 64-bit systems with size_t of 8 bytes are not vulnerable, and systems using default ImageMagick resource limits are not vulnerable. The vulnerability is fixed in versions 7.1.2-7 and 6.9.13-32."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-62171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-62171","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"risk":0.40449999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-62171"},"relatedVulnerabilities":[{"id":"CVE-2025-62171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cea1693e2ded51b4cc91c70c54096cbed1691c00","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9pp9-cfwx-54rm","https://lists.debian.org/debian-lts-announce/2025/10/msg00019.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-62171","description":"ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vulnerability only affects 32-bit builds of ImageMagick where default resource limits for width, height, and area have been manually increased beyond their defaults. 64-bit systems with size_t of 8 bytes are not vulnerable, and systems using default ImageMagick resource limits are not vulnerable. The vulnerability is fixed in versions 7.1.2-7 and 6.9.13-32."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-62171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-62171","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"risk":0.40449999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-62171"},"relatedVulnerabilities":[{"id":"CVE-2025-62171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cea1693e2ded51b4cc91c70c54096cbed1691c00","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9pp9-cfwx-54rm","https://lists.debian.org/debian-lts-announce/2025/10/msg00019.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-62171","description":"ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vulnerability only affects 32-bit builds of ImageMagick where default resource limits for width, height, and area have been manually increased beyond their defaults. 64-bit systems with size_t of 8 bytes are not vulnerable, and systems using default ImageMagick resource limits are not vulnerable. The vulnerability is fixed in versions 7.1.2-7 and 6.9.13-32."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-62171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-62171","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"risk":0.40449999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-62171"},"relatedVulnerabilities":[{"id":"CVE-2025-62171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cea1693e2ded51b4cc91c70c54096cbed1691c00","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9pp9-cfwx-54rm","https://lists.debian.org/debian-lts-announce/2025/10/msg00019.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-62171","description":"ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vulnerability only affects 32-bit builds of ImageMagick where default resource limits for width, height, and area have been manually increased beyond their defaults. 64-bit systems with size_t of 8 bytes are not vulnerable, and systems using default ImageMagick resource limits are not vulnerable. The vulnerability is fixed in versions 7.1.2-7 and 6.9.13-32."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-62171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-62171","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"risk":0.40449999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-62171"},"relatedVulnerabilities":[{"id":"CVE-2025-62171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-62171","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-62171","date":"2026-10-08","epss":0.00809,"percentile":0.55582}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/cea1693e2ded51b4cc91c70c54096cbed1691c00","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9pp9-cfwx-54rm","https://lists.debian.org/debian-lts-announce/2025/10/msg00019.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-62171","description":"ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exists in the BMP decoder on 32-bit systems. The vulnerability occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. On 32-bit systems with size_t of 4 bytes, a malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check added to address CVE-2025-57803 is placed after the overflow occurs, making it ineffective. A specially crafted 58-byte BMP file with width set to 536,870,912 and 32 bits per pixel can trigger this overflow, causing the bytes_per_line calculation to become zero. This vulnerability only affects 32-bit builds of ImageMagick where default resource limits for width, height, and area have been manually increased beyond their defaults. 64-bit systems with size_t of 8 bytes are not vulnerable, and systems using default ImageMagick resource limits are not vulnerable. The vulnerability is fixed in versions 7.1.2-7 and 6.9.13-32."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"risk":0.39449999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25965"},"relatedVulnerabilities":[{"id":"CVE-2026-25965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8jvj-p28h-9gm7","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25965","https://bugzilla.redhat.com/show_bug.cgi?id=2442118","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25965.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25965","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. This will also be included in ImageMagick's more secure policies by default."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"risk":0.39449999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25965"},"relatedVulnerabilities":[{"id":"CVE-2026-25965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8jvj-p28h-9gm7","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25965","https://bugzilla.redhat.com/show_bug.cgi?id=2442118","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25965.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25965","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. This will also be included in ImageMagick's more secure policies by default."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"risk":0.39449999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25965"},"relatedVulnerabilities":[{"id":"CVE-2026-25965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8jvj-p28h-9gm7","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25965","https://bugzilla.redhat.com/show_bug.cgi?id=2442118","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25965.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25965","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. This will also be included in ImageMagick's more secure policies by default."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"risk":0.39449999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25965"},"relatedVulnerabilities":[{"id":"CVE-2026-25965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8jvj-p28h-9gm7","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25965","https://bugzilla.redhat.com/show_bug.cgi?id=2442118","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25965.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25965","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. This will also be included in ImageMagick's more secure policies by default."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"risk":0.39449999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25965"},"relatedVulnerabilities":[{"id":"CVE-2026-25965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25965","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25965","date":"2026-10-08","epss":0.00789,"percentile":0.54891}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8jvj-p28h-9gm7","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25965","https://bugzilla.redhat.com/show_bug.cgi?id=2442118","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25965.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25965","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’s path security policy is enforced on the raw filename string before the filesystem resolves it. As a result, a policy rule such as /etc/* can be bypassed by a path traversal. The OS resolves the traversal and opens the sensitive file, but the policy matcher only sees the unnormalized path and therefore allows the read. This enables local file disclosure (LFI) even when policy-secure.xml is applied. Actions to prevent reading from files have been taken in versions .7.1.2-15 and 6.9.13-40 But it make sure writing is also not possible the following should be added to one's policy. This will also be included in ImageMagick's more secure policies by default."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3751","versionConstraint":"<1.23.10||>=1.24.0-0,<1.24.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3751","fix":{"state":"fixed","versions":["1.23.10","1.24.4"],"available":[{"date":"2025-06-05","kind":"release","version":"1.23.10"},{"date":"2025-06-05","kind":"release","version":"1.24.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-4673","date":"2026-10-08","epss":0.00666,"percentile":0.50281}],"risk":0.39293999999999996,"urls":["https://go.dev/issue/73816","https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/679257","description":"Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2025-4673","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-4673","date":"2026-10-08","epss":0.00666,"percentile":0.50281}],"urls":["https://go.dev/cl/679257","https://go.dev/issue/73816","https://groups.google.com/g/golang-announce/c/ufZ8WpEsA3A","https://pkg.go.dev/vuln/GO-2025-3751"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4673","description":"Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-3105","versionConstraint":"<1.22.7||>=1.23.0-0,<1.23.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-3105","fix":{"state":"fixed","versions":["1.22.7","1.23.1"],"available":[{"date":"2024-09-05","kind":"release","version":"1.22.7"},{"date":"2024-09-05","kind":"release","version":"1.23.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34155","date":"2026-10-08","epss":0.00839,"percentile":0.56543}],"risk":0.39013499999999995,"urls":["https://go.dev/issue/69138","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/611238","description":"Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2024-34155","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-34155","date":"2026-10-08","epss":0.00839,"percentile":0.56543}],"urls":["https://go.dev/cl/611238","https://go.dev/issue/69138","https://groups.google.com/g/golang-dev/c/S9POB9NCTdk","https://pkg.go.dev/vuln/GO-2024-3105","https://security.netapp.com/advisory/ntap-20240926-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34155","description":"Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3420","versionConstraint":"<1.22.11||>=1.23.0-0,<1.23.5||>=1.24.0-0,<1.24.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3420","fix":{"state":"fixed","versions":["1.22.11","1.23.5","1.24.0-rc.2"],"available":[{"date":"2025-01-16","kind":"release","version":"1.22.11"},{"date":"2025-01-16","kind":"release","version":"1.23.5"},{"date":"2025-01-16","kind":"release","version":"1.24.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45336","date":"2026-10-08","epss":0.00671,"percentile":0.50497}],"risk":0.372405,"urls":["https://go.dev/issue/70530","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/643100","description":"The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com.\n\nIn the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2."},"relatedVulnerabilities":[{"id":"CVE-2024-45336","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45336","date":"2026-10-08","epss":0.00671,"percentile":0.50497}],"urls":["https://go.dev/cl/643100","https://go.dev/issue/70530","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ","https://pkg.go.dev/vuln/GO-2025-3420","https://security.netapp.com/advisory/ntap-20250221-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-45336","description":"The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33901","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33901","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"risk":0.37,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33901"},"relatedVulnerabilities":[{"id":"CVE-2026-33901","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33901","https://bugzilla.redhat.com/show_bug.cgi?id=2458023","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33901.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33901","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33901","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33901","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"risk":0.37,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33901"},"relatedVulnerabilities":[{"id":"CVE-2026-33901","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33901","https://bugzilla.redhat.com/show_bug.cgi?id=2458023","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33901.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33901","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33901","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33901","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"risk":0.37,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33901"},"relatedVulnerabilities":[{"id":"CVE-2026-33901","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33901","https://bugzilla.redhat.com/show_bug.cgi?id=2458023","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33901.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33901","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33901","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33901","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"risk":0.37,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33901"},"relatedVulnerabilities":[{"id":"CVE-2026-33901","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33901","https://bugzilla.redhat.com/show_bug.cgi?id=2458023","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33901.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33901","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33901","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33901","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"risk":0.37,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33901"},"relatedVulnerabilities":[{"id":"CVE-2026-33901","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33901","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33901","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33901","date":"2026-10-08","epss":0.0074,"percentile":0.53192}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33901","https://bugzilla.redhat.com/show_bug.cgi?id=2458023","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33901.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33901","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.14.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-55h5-xmcq-c37v","versionConstraint":"<6.14.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-55h5-xmcq-c37v","fix":{"state":"fixed","versions":["6.14.0"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"6.14.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59937","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59937","date":"2026-10-08","epss":0.0062,"percentile":0.48081}],"risk":0.36889999999999995,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-55h5-xmcq-c37v","https://nvd.nist.gov/vuln/detail/CVE-2026-59937","https://github.com/py-pdf/pypdf/pull/3887","https://github.com/py-pdf/pypdf/commit/b5fc5aa714f4b696fb9b1deaa35a9e4a4eb50dae","https://github.com/py-pdf/pypdf/releases/tag/6.14.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-55h5-xmcq-c37v","description":"pypdf: Possible long runtimes for repeated malformed cross-reference entries"},"relatedVulnerabilities":[{"id":"CVE-2026-59937","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59937","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59937","date":"2026-10-08","epss":0.0062,"percentile":0.48081}],"urls":["https://github.com/py-pdf/pypdf/commit/b5fc5aa714f4b696fb9b1deaa35a9e4a4eb50dae","https://github.com/py-pdf/pypdf/pull/3887","https://github.com/py-pdf/pypdf/releases/tag/6.14.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-55h5-xmcq-c37v"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59937","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams that cause pypdf to spend long runtimes recovering broken cross-reference table entries. This issue is fixed in version 6.14.0."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2598","versionConstraint":"<1.21.8||>=1.22.0-0,<1.22.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2598","fix":{"state":"fixed","versions":["1.21.8","1.22.1"],"available":[{"date":"2024-03-05","kind":"release","version":"1.21.8"},{"date":"2024-03-05","kind":"release","version":"1.22.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24783","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-24783","date":"2026-10-08","epss":0.00667,"percentile":0.50323}],"risk":0.36351500000000003,"urls":["https://go.dev/cl/569339","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/65390","description":"Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic.\n\nThis affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates."},"relatedVulnerabilities":[{"id":"CVE-2024-24783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-24783","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-24783","date":"2026-10-08","epss":0.00667,"percentile":0.50323}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/08/4","https://go.dev/cl/569339","https://go.dev/issue/65390","https://groups.google.com/g/golang-announce/c/5pwGVUPoMbg","https://pkg.go.dev/vuln/GO-2024-2598","https://security.netapp.com/advisory/ntap-20240329-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24783","description":"Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2020-25664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2020-25664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"risk":0.3595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25664"},"relatedVulnerabilities":[{"id":"CVE-2020-25664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1891605","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z3J6D7POCQYQKNVRDYLTTPM5SQC3WVTR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25664","description":"In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2020-25664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"risk":0.3595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25664"},"relatedVulnerabilities":[{"id":"CVE-2020-25664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1891605","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z3J6D7POCQYQKNVRDYLTTPM5SQC3WVTR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25664","description":"In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2020-25664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"risk":0.3595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25664"},"relatedVulnerabilities":[{"id":"CVE-2020-25664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1891605","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z3J6D7POCQYQKNVRDYLTTPM5SQC3WVTR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25664","description":"In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2020-25664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"risk":0.3595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25664"},"relatedVulnerabilities":[{"id":"CVE-2020-25664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1891605","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z3J6D7POCQYQKNVRDYLTTPM5SQC3WVTR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25664","description":"In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-25664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2020-25664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"risk":0.3595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2020-25664"},"relatedVulnerabilities":[{"id":"CVE-2020-25664","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-25664","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2020-25664","date":"2026-10-08","epss":0.00719,"percentile":0.52449}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1891605","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z3J6D7POCQYQKNVRDYLTTPM5SQC3WVTR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-25664","description":"In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"2c249697e195b912","cpes":["cpe:2.3:a:golang:text:v0.3.6:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.3.6","type":"go-module","version":"v0.3.6","language":"go","licenses":[],"metadata":{"h1Digest":"h1:aRYxNxv6iGQlyVaZmk6ZgYEDa+Jg18DxebPSrd6bg1M=","mainModule":"github.com/pgaskin/kepubify/v4","architecture":"x86_64","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.39.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5970","versionConstraint":"<0.39.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.3.6"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5970","fix":{"state":"fixed","versions":["0.39.0"],"available":[{"date":"2026-06-30","kind":"release","version":"0.39.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"risk":0.35624999999999996,"urls":["https://go.dev/cl/794100"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80142","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-56852","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"urls":["https://go.dev/cl/794100","https://go.dev/issue/80142","https://pkg.go.dev/vuln/GO-2026-5970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56852","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45031","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45031","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"risk":0.3535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45031"},"relatedVulnerabilities":[{"id":"CVE-2026-45031","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cwpj-h54c-xjpx","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45031","https://bugzilla.redhat.com/show_bug.cgi?id=2487734","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45031.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45031","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45031","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45031","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"risk":0.3535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45031"},"relatedVulnerabilities":[{"id":"CVE-2026-45031","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cwpj-h54c-xjpx","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45031","https://bugzilla.redhat.com/show_bug.cgi?id=2487734","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45031.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45031","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45031","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45031","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"risk":0.3535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45031"},"relatedVulnerabilities":[{"id":"CVE-2026-45031","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cwpj-h54c-xjpx","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45031","https://bugzilla.redhat.com/show_bug.cgi?id=2487734","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45031.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45031","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45031","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45031","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"risk":0.3535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45031"},"relatedVulnerabilities":[{"id":"CVE-2026-45031","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cwpj-h54c-xjpx","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45031","https://bugzilla.redhat.com/show_bug.cgi?id=2487734","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45031.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45031","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45031","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45031","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"risk":0.3535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45031"},"relatedVulnerabilities":[{"id":"CVE-2026-45031","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45031","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45031","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45031","date":"2026-10-08","epss":0.00707,"percentile":0.5201}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cwpj-h54c-xjpx","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45031","https://bugzilla.redhat.com/show_bug.cgi?id=2487734","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45031.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45031","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible to bypass the list-length resource policy when decoding a PSD image. Other security limits would still apply. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33908","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33908","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"risk":0.35000000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33908"},"relatedVulnerabilities":[{"id":"CVE-2026-33908","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwvm-ggf6-2p4x","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33908","https://bugzilla.redhat.com/show_bug.cgi?id=2458041","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33908.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33908","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33908","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33908","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"risk":0.35000000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33908"},"relatedVulnerabilities":[{"id":"CVE-2026-33908","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwvm-ggf6-2p4x","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33908","https://bugzilla.redhat.com/show_bug.cgi?id=2458041","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33908.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33908","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33908","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33908","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"risk":0.35000000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33908"},"relatedVulnerabilities":[{"id":"CVE-2026-33908","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwvm-ggf6-2p4x","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33908","https://bugzilla.redhat.com/show_bug.cgi?id=2458041","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33908.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33908","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33908","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33908","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"risk":0.35000000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33908"},"relatedVulnerabilities":[{"id":"CVE-2026-33908","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwvm-ggf6-2p4x","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33908","https://bugzilla.redhat.com/show_bug.cgi?id=2458041","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33908.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33908","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33908","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33908","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"risk":0.35000000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33908"},"relatedVulnerabilities":[{"id":"CVE-2026-33908","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33908","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33908","cwe":"CWE-776","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33908","date":"2026-10-08","epss":0.007,"percentile":0.51708}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ccdc01180276aa2cb3d4a32a611aa4f417061cd8","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwvm-ggf6-2p4x","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0","https://access.redhat.com/security/cve/CVE-2026-33908","https://bugzilla.redhat.com/show_bug.cgi?id=2458041","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33908.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33908","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tree via the `DestroyXMLTree()` function; however, this process is executed recursively with no depth limit imposed. When Magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2022-0531","versionConstraint":"<1.17.11||>=1.18.0-0,<1.18.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2022-0531","fix":{"state":"fixed","versions":["1.17.11","1.18.3"],"available":[{"date":"2022-06-01","kind":"release","version":"1.17.11"},{"date":"2022-06-01","kind":"release","version":"1.18.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30629","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30629","date":"2026-10-08","epss":0.01143,"percentile":0.65717}],"risk":0.34861499999999995,"urls":["https://go.googlesource.com/go/+/fe4de36198794c447fbd9d7cc2d7199a506c76a5","https://go.dev/issue/52814","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/405994","description":"An attacker can correlate a resumed TLS session with a previous connection.\n\nSession tickets generated by crypto/tls do not contain a randomly generated ticket_age_add, which allows an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption."},"relatedVulnerabilities":[{"id":"CVE-2022-30629","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-30629","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-30629","date":"2026-10-08","epss":0.01143,"percentile":0.65717}],"urls":["https://go.dev/cl/405994","https://go.dev/issue/52814","https://go.googlesource.com/go/+/fe4de36198794c447fbd9d7cc2d7199a506c76a5","https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ","https://pkg.go.dev/vuln/GO-2022-0531"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-30629","description":"Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4155","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4155","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"risk":0.34275,"urls":["https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/725920","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"urls":["https://go.dev/cl/725920","https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4155"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61729","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-53014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53014","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"risk":0.34199999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53014"},"relatedVulnerabilities":[{"id":"CVE-2025-53014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hm4x-r5hc-794f","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53014","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (`%%`). Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53014","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"risk":0.34199999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53014"},"relatedVulnerabilities":[{"id":"CVE-2025-53014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hm4x-r5hc-794f","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53014","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (`%%`). Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53014","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"risk":0.34199999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53014"},"relatedVulnerabilities":[{"id":"CVE-2025-53014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hm4x-r5hc-794f","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53014","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (`%%`). Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53014","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"risk":0.34199999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53014"},"relatedVulnerabilities":[{"id":"CVE-2025-53014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hm4x-r5hc-794f","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53014","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (`%%`). Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53014","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53014","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"risk":0.34199999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53014"},"relatedVulnerabilities":[{"id":"CVE-2025-53014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53014","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53014","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-53014","date":"2026-10-08","epss":0.00684,"percentile":0.51092}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hm4x-r5hc-794f","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53014","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (`%%`). Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66418","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66418","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66418","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66418","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"risk":0.34099999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66418"},"relatedVulnerabilities":[{"id":"CVE-2025-66418","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66418","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66418","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"urls":["https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8","https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66471","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66471","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66471","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"risk":0.34099999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66471"},"relatedVulnerabilities":[{"id":"CVE-2025-66471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66471","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66471","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"urls":["https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7","https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-23876","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23876","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"risk":0.33149999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23876"},"relatedVulnerabilities":[{"id":"CVE-2026-23876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2fae24192b78fdfdd27d766fd21d90aeac6ea8b8","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r49w-jqq3-3gx8","https://access.redhat.com/errata/RHSA-2026:3058","https://access.redhat.com/security/cve/CVE-2026-23876","https://bugzilla.redhat.com/show_bug.cgi?id=2431038","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23876.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23876","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23876","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23876","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"risk":0.33149999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23876"},"relatedVulnerabilities":[{"id":"CVE-2026-23876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2fae24192b78fdfdd27d766fd21d90aeac6ea8b8","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r49w-jqq3-3gx8","https://access.redhat.com/errata/RHSA-2026:3058","https://access.redhat.com/security/cve/CVE-2026-23876","https://bugzilla.redhat.com/show_bug.cgi?id=2431038","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23876.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23876","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23876","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23876","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"risk":0.33149999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23876"},"relatedVulnerabilities":[{"id":"CVE-2026-23876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2fae24192b78fdfdd27d766fd21d90aeac6ea8b8","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r49w-jqq3-3gx8","https://access.redhat.com/errata/RHSA-2026:3058","https://access.redhat.com/security/cve/CVE-2026-23876","https://bugzilla.redhat.com/show_bug.cgi?id=2431038","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23876.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23876","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23876","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23876","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"risk":0.33149999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23876"},"relatedVulnerabilities":[{"id":"CVE-2026-23876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2fae24192b78fdfdd27d766fd21d90aeac6ea8b8","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r49w-jqq3-3gx8","https://access.redhat.com/errata/RHSA-2026:3058","https://access.redhat.com/security/cve/CVE-2026-23876","https://bugzilla.redhat.com/show_bug.cgi?id=2431038","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23876.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23876","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23876","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23876","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"risk":0.33149999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23876"},"relatedVulnerabilities":[{"id":"CVE-2026-23876","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23876","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-23876","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-23876","date":"2026-10-08","epss":0.00663,"percentile":0.50141}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2fae24192b78fdfdd27d766fd21d90aeac6ea8b8","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r49w-jqq3-3gx8","https://access.redhat.com/errata/RHSA-2026:3058","https://access.redhat.com/security/cve/CVE-2026-23876","https://bugzilla.redhat.com/show_bug.cgi?id=2431038","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23876.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23876","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25985","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25985","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25985"},"relatedVulnerabilities":[{"id":"CVE-2026-25985","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v7g2-m8c5-mf84","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25985","https://bugzilla.redhat.com/show_bug.cgi?id=2442127","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25985.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25985","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25985","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25985","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25985"},"relatedVulnerabilities":[{"id":"CVE-2026-25985","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v7g2-m8c5-mf84","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25985","https://bugzilla.redhat.com/show_bug.cgi?id=2442127","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25985.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25985","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25985","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25985","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25985"},"relatedVulnerabilities":[{"id":"CVE-2026-25985","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v7g2-m8c5-mf84","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25985","https://bugzilla.redhat.com/show_bug.cgi?id=2442127","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25985.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25985","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25985","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25985","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25985"},"relatedVulnerabilities":[{"id":"CVE-2026-25985","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v7g2-m8c5-mf84","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25985","https://bugzilla.redhat.com/show_bug.cgi?id=2442127","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25985.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25985","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25985","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25985","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25985"},"relatedVulnerabilities":[{"id":"CVE-2026-25985","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25985","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25985","date":"2026-10-08","epss":0.00662,"percentile":0.50107}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v7g2-m8c5-mf84","https://access.redhat.com/errata/RHSA-2026:5573","https://access.redhat.com/security/cve/CVE-2026-25985","https://bugzilla.redhat.com/show_bug.cgi?id=2442127","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25985.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25985","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file containing an malicious element causes ImageMagick to attempt to allocate ~674 GB of memory, leading to an out-of-memory abort. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.19.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2023-1840","versionConstraint":"<1.19.10||>=1.20.0-0,<1.20.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2023-1840","fix":{"state":"fixed","versions":["1.19.10","1.20.5"],"available":[{"date":"2023-06-06","kind":"release","version":"1.19.10"},{"date":"2023-06-06","kind":"release","version":"1.20.5"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29403","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29403","date":"2026-10-08","epss":0.00429,"percentile":0.35103}],"risk":0.328185,"urls":["https://go.dev/cl/501223","https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJ"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/60272","description":"On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors.\n\nIf a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers."},"relatedVulnerabilities":[{"id":"CVE-2023-29403","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29403","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29403","date":"2026-10-08","epss":0.00429,"percentile":0.35103}],"urls":["https://go.dev/cl/501223","https://go.dev/issue/60272","https://groups.google.com/g/golang-announce/c/q5135a9d924/m/j0ZoAJOHAwAJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZ2O6YCO2IZMZJELQGZYR2WAUNEDLYV6/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XBS3IIK6ADV24C5ULQU55QLT2UE762ZX/","https://pkg.go.dev/vuln/GO-2023-1840","https://security.gentoo.org/glsa/202311-09","https://security.netapp.com/advisory/ntap-20241220-0009/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29403","description":"On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result in unexpected content being read or written with elevated privileges. Similarly, if a setuid/setgid program is terminated, either via panic or signal, it may leak the contents of its registers."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28691","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28691","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"risk":0.327,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28691"},"relatedVulnerabilities":[{"id":"CVE-2026-28691","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28691","https://bugzilla.redhat.com/show_bug.cgi?id=2445902","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28691.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28691","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28691","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28691","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"risk":0.327,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28691"},"relatedVulnerabilities":[{"id":"CVE-2026-28691","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28691","https://bugzilla.redhat.com/show_bug.cgi?id=2445902","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28691.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28691","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28691","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28691","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"risk":0.327,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28691"},"relatedVulnerabilities":[{"id":"CVE-2026-28691","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28691","https://bugzilla.redhat.com/show_bug.cgi?id=2445902","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28691.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28691","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28691","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28691","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"risk":0.327,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28691"},"relatedVulnerabilities":[{"id":"CVE-2026-28691","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28691","https://bugzilla.redhat.com/show_bug.cgi?id=2445902","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28691.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28691","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28691","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28691","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"risk":0.327,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28691"},"relatedVulnerabilities":[{"id":"CVE-2026-28691","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28691","cwe":"CWE-252","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28691","cwe":"CWE-824","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28691","date":"2026-10-08","epss":0.00654,"percentile":0.49776}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wj8w-pjxf-9g4f","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28691","https://bugzilla.redhat.com/show_bug.cgi?id=2445902","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28691.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28691","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an uninitialized pointer dereference vulnerability exists in the JBIG decoder due to a missing check. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-68618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-68618","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"risk":0.3235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-68618"},"relatedVulnerabilities":[{"id":"CVE-2025-68618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/6f431d445f3ddd609c004a1dde617b0a73e60beb","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p27m-hp98-6637"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68618","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-68618","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"risk":0.3235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-68618"},"relatedVulnerabilities":[{"id":"CVE-2025-68618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/6f431d445f3ddd609c004a1dde617b0a73e60beb","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p27m-hp98-6637"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68618","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-68618","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"risk":0.3235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-68618"},"relatedVulnerabilities":[{"id":"CVE-2025-68618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/6f431d445f3ddd609c004a1dde617b0a73e60beb","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p27m-hp98-6637"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68618","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-68618","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"risk":0.3235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-68618"},"relatedVulnerabilities":[{"id":"CVE-2025-68618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/6f431d445f3ddd609c004a1dde617b0a73e60beb","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p27m-hp98-6637"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68618","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-68618","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-68618","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"risk":0.3235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-68618"},"relatedVulnerabilities":[{"id":"CVE-2025-68618","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68618","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-68618","date":"2026-10-08","epss":0.00647,"percentile":0.49413}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/6f431d445f3ddd609c004a1dde617b0a73e60beb","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p27m-hp98-6637"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68618","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3956","versionConstraint":"<1.23.12||>=1.24.0,<1.24.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3956","fix":{"state":"fixed","versions":["1.23.12","1.24.6"],"available":[{"date":"2025-08-06","kind":"release","version":"1.23.12"},{"date":"2025-08-06","kind":"release","version":"1.24.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47906","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47906","date":"2026-10-08","epss":0.0055,"percentile":0.44269}],"risk":0.31625,"urls":["https://go.dev/issue/74466","https://groups.google.com/g/golang-announce/c/x5MKroML2yM"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/691775","description":"If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (\"\", \".\", and \"..\"), can result in the binaries listed in the PATH being unexpectedly returned."},"relatedVulnerabilities":[{"id":"CVE-2025-47906","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47906","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47906","date":"2026-10-08","epss":0.0055,"percentile":0.44269}],"urls":["https://go.dev/cl/691775","https://go.dev/issue/74466","https://groups.google.com/g/golang-announce/c/x5MKroML2yM","https://pkg.go.dev/vuln/GO-2025-3956","http://www.openwall.com/lists/oss-security/2025/08/06/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47906","description":"If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath (\"\", \".\", and \"..\"), can result in the binaries listed in the PATH being unexpectedly returned."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-46520","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46520","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46520"},"relatedVulnerabilities":[{"id":"CVE-2026-46520","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-36wm-hprc-mcf5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46520","https://bugzilla.redhat.com/show_bug.cgi?id=2487729","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46520.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46520","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46520","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46520","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46520"},"relatedVulnerabilities":[{"id":"CVE-2026-46520","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-36wm-hprc-mcf5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46520","https://bugzilla.redhat.com/show_bug.cgi?id=2487729","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46520.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46520","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46520","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46520","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46520"},"relatedVulnerabilities":[{"id":"CVE-2026-46520","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-36wm-hprc-mcf5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46520","https://bugzilla.redhat.com/show_bug.cgi?id=2487729","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46520.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46520","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46520","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46520","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46520"},"relatedVulnerabilities":[{"id":"CVE-2026-46520","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-36wm-hprc-mcf5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46520","https://bugzilla.redhat.com/show_bug.cgi?id=2487729","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46520.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46520","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46520","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46520","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46520"},"relatedVulnerabilities":[{"id":"CVE-2026-46520","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46520","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46520","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46520","date":"2026-10-08","epss":0.0063,"percentile":0.48576}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-36wm-hprc-mcf5","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46520","https://bugzilla.redhat.com/show_bug.cgi?id=2487729","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46520.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46520","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out of bounds heap write can occur. This issue has been patched in versions 6.9.13-48 and 7.1.2-23."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53461"},"relatedVulnerabilities":[{"id":"CVE-2026-53461","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g22q-f7gc-5jhr","https://access.redhat.com/security/cve/CVE-2026-53461","https://bugzilla.redhat.com/show_bug.cgi?id=2487764","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53461.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53461","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53461"},"relatedVulnerabilities":[{"id":"CVE-2026-53461","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g22q-f7gc-5jhr","https://access.redhat.com/security/cve/CVE-2026-53461","https://bugzilla.redhat.com/show_bug.cgi?id=2487764","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53461.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53461","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53461"},"relatedVulnerabilities":[{"id":"CVE-2026-53461","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g22q-f7gc-5jhr","https://access.redhat.com/security/cve/CVE-2026-53461","https://bugzilla.redhat.com/show_bug.cgi?id=2487764","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53461.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53461","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53461"},"relatedVulnerabilities":[{"id":"CVE-2026-53461","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g22q-f7gc-5jhr","https://access.redhat.com/security/cve/CVE-2026-53461","https://bugzilla.redhat.com/show_bug.cgi?id=2487764","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53461.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53461","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53461"},"relatedVulnerabilities":[{"id":"CVE-2026-53461","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53461","cwe":"CWE-787","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53461","date":"2026-10-08","epss":0.0063,"percentile":0.48574}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g22q-f7gc-5jhr","https://access.redhat.com/security/cve/CVE-2026-53461","https://bugzilla.redhat.com/show_bug.cgi?id=2487764","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53461.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53461","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53460","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53460","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53460"},"relatedVulnerabilities":[{"id":"CVE-2026-53460","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q62c-h75r-2xhc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-53460","https://bugzilla.redhat.com/show_bug.cgi?id=2487757","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53460.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53460","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53460","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53460","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53460"},"relatedVulnerabilities":[{"id":"CVE-2026-53460","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q62c-h75r-2xhc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-53460","https://bugzilla.redhat.com/show_bug.cgi?id=2487757","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53460.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53460","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53460","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53460","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53460"},"relatedVulnerabilities":[{"id":"CVE-2026-53460","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q62c-h75r-2xhc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-53460","https://bugzilla.redhat.com/show_bug.cgi?id=2487757","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53460.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53460","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53460","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53460","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53460"},"relatedVulnerabilities":[{"id":"CVE-2026-53460","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q62c-h75r-2xhc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-53460","https://bugzilla.redhat.com/show_bug.cgi?id=2487757","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53460.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53460","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53460","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53460","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53460"},"relatedVulnerabilities":[{"id":"CVE-2026-53460","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-53460","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-53460","date":"2026-10-08","epss":0.0063,"percentile":0.48573}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-q62c-h75r-2xhc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-53460","https://bugzilla.redhat.com/show_bug.cgi?id=2487757","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53460.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53460","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-49218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49218","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49218"},"relatedVulnerabilities":[{"id":"CVE-2026-49218","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8pj9-6897-74xc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-49218","https://bugzilla.redhat.com/show_bug.cgi?id=2487763","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49218.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49218","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49218","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49218"},"relatedVulnerabilities":[{"id":"CVE-2026-49218","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8pj9-6897-74xc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-49218","https://bugzilla.redhat.com/show_bug.cgi?id=2487763","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49218.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49218","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49218","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49218"},"relatedVulnerabilities":[{"id":"CVE-2026-49218","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8pj9-6897-74xc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-49218","https://bugzilla.redhat.com/show_bug.cgi?id=2487763","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49218.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49218","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49218","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49218"},"relatedVulnerabilities":[{"id":"CVE-2026-49218","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8pj9-6897-74xc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-49218","https://bugzilla.redhat.com/show_bug.cgi?id=2487763","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49218.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49218","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49218","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49218","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49218"},"relatedVulnerabilities":[{"id":"CVE-2026-49218","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49218","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-49218","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-49218","date":"2026-10-08","epss":0.0063,"percentile":0.4856}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8pj9-6897-74xc","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-49218","https://bugzilla.redhat.com/show_bug.cgi?id=2487763","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49218.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49218","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45664"},"relatedVulnerabilities":[{"id":"CVE-2026-45664","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g5mf-wqq5-vwg6","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45664","https://bugzilla.redhat.com/show_bug.cgi?id=2487732","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45664.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45664","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45664"},"relatedVulnerabilities":[{"id":"CVE-2026-45664","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g5mf-wqq5-vwg6","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45664","https://bugzilla.redhat.com/show_bug.cgi?id=2487732","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45664.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45664","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45664"},"relatedVulnerabilities":[{"id":"CVE-2026-45664","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g5mf-wqq5-vwg6","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45664","https://bugzilla.redhat.com/show_bug.cgi?id=2487732","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45664.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45664","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45664"},"relatedVulnerabilities":[{"id":"CVE-2026-45664","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g5mf-wqq5-vwg6","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45664","https://bugzilla.redhat.com/show_bug.cgi?id=2487732","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45664.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45664","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45664","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45664","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45664"},"relatedVulnerabilities":[{"id":"CVE-2026-45664","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45664","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45664","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45664","date":"2026-10-08","epss":0.0063,"percentile":0.48557}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g5mf-wqq5-vwg6","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-45664","https://bugzilla.redhat.com/show_bug.cgi?id=2487732","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45664.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45664","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use. This issue has been patched in versions 6.9.13-47 and 7.1.2-22."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.15.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fc8x-2rww-xw9m","versionConstraint":"<6.15.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-fc8x-2rww-xw9m","fix":{"state":"fixed","versions":["6.15.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"6.15.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82398","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-82398","date":"2026-10-08","epss":0.00524,"percentile":0.42601}],"risk":0.31177999999999995,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m","https://nvd.nist.gov/vuln/detail/CVE-2026-82398","https://github.com/py-pdf/pypdf/pull/3947","https://github.com/py-pdf/pypdf/commit/4959848e057e37c218dccad7465259210923faaa","https://github.com/py-pdf/pypdf/releases/tag/6.15.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fc8x-2rww-xw9m","description":"pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace"},"relatedVulnerabilities":[{"id":"CVE-2026-82398","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82398","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-82398","date":"2026-10-08","epss":0.00524,"percentile":0.42601}],"urls":["https://github.com/py-pdf/pypdf/commit/4959848e057e37c218dccad7465259210923faaa","https://github.com/py-pdf/pypdf/pull/3947","https://github.com/py-pdf/pypdf/releases/tag/6.15.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82398","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly performs immutable bytes concatenation in a one-byte loop, causing quadratic processing cost for the long non-whitespace input. This issue is fixed in version 6.15.0."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.14.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5qjq-93h5-hrgp","versionConstraint":"<6.14.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-5qjq-93h5-hrgp","fix":{"state":"fixed","versions":["6.14.0"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"6.14.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59938","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59938","date":"2026-10-08","epss":0.00515,"percentile":0.42037}],"risk":0.30642499999999995,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgp","https://nvd.nist.gov/vuln/detail/CVE-2026-59938","https://github.com/py-pdf/pypdf/pull/3888","https://github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7a","https://github.com/py-pdf/pypdf/releases/tag/6.14.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5qjq-93h5-hrgp","description":"pypdf: Possible large memory usage for wrong image dimensions"},"relatedVulnerabilities":[{"id":"CVE-2026-59938","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59938","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59938","date":"2026-10-08","epss":0.00515,"percentile":0.42037}],"urls":["https://github.com/py-pdf/pypdf/commit/c64583be16b8e8763d8777075f8ecbf382014b7a","https://github.com/py-pdf/pypdf/pull/3888","https://github.com/py-pdf/pypdf/releases/tag/6.14.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-5qjq-93h5-hrgp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59938","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared image size values that are much too large compared to the actual data, causing large memory usage in pypdf image parsing. This issue is fixed in version 6.14.0."}]},{"artifact":{"id":"40beb4f8a2ae0009","cpes":["cpe:2.3:a:cryptography.io:cryptography:43.0.3:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:43.0.3:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@43.0.3","type":"python","version":"43.0.3","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"46.0.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r6ph-v2qm-q3c2","versionConstraint":"<=46.0.4 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"43.0.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-r6ph-v2qm-q3c2","fix":{"state":"fixed","versions":["46.0.5"],"available":[{"date":"2026-02-11","kind":"first-observed","version":"46.0.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26007","cwe":"CWE-345","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26007","cwe":"CWE-354","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-26007","date":"2026-10-08","epss":0.00389,"percentile":0.30873}],"risk":0.30536499999999994,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2","https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c","https://github.com/pyca/cryptography/releases/tag/46.0.5","https://nvd.nist.gov/vuln/detail/CVE-2026-26007","http://www.openwall.com/lists/oss-security/2026/02/10/4"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r6ph-v2qm-q3c2","description":"cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves"},"relatedVulnerabilities":[{"id":"CVE-2026-26007","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26007","cwe":"CWE-345","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26007","cwe":"CWE-354","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-26007","date":"2026-10-08","epss":0.00389,"percentile":0.30873}],"urls":["https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c","https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2","http://www.openwall.com/lists/oss-security/2026/02/10/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:12176","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13553","https://access.redhat.com/errata/RHSA-2026:13672","https://access.redhat.com/errata/RHSA-2026:19355","https://access.redhat.com/errata/RHSA-2026:21431","https://access.redhat.com/errata/RHSA-2026:21517","https://access.redhat.com/errata/RHSA-2026:22330","https://access.redhat.com/errata/RHSA-2026:22993","https://access.redhat.com/errata/RHSA-2026:2694","https://access.redhat.com/errata/RHSA-2026:5168","https://access.redhat.com/errata/RHSA-2026:5665","https://access.redhat.com/errata/RHSA-2026:6308","https://access.redhat.com/errata/RHSA-2026:6309","https://access.redhat.com/errata/RHSA-2026:6497","https://access.redhat.com/errata/RHSA-2026:6567","https://access.redhat.com/errata/RHSA-2026:6568","https://access.redhat.com/errata/RHSA-2026:7295","https://access.redhat.com/security/cve/CVE-2026-26007","https://bugzilla.redhat.com/show_bug.cgi?id=2438762","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26007","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4007","versionConstraint":"<1.24.9||>=1.25.0,<1.25.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4007","fix":{"state":"fixed","versions":["1.24.9","1.25.3"],"available":[{"date":"2025-10-13","kind":"release","version":"1.24.9"},{"date":"2025-10-13","kind":"release","version":"1.25.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"risk":0.3045,"urls":["https://go.dev/cl/709854","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75681","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58187","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58187","cwe":"CWE-407","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58187","date":"2026-10-08","epss":0.00406,"percentile":0.32778}],"urls":["https://go.dev/cl/709854","https://go.dev/issue/75681","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4007","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58187","description":"Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-32636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-32636"},"relatedVulnerabilities":[{"id":"CVE-2026-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"urls":["https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-17","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gc62-2v5p-qpmp","https://github.com/dlemstra/Magick.NET/releases/tag/14.11.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32636","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-32636"},"relatedVulnerabilities":[{"id":"CVE-2026-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"urls":["https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-17","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gc62-2v5p-qpmp","https://github.com/dlemstra/Magick.NET/releases/tag/14.11.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32636","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-32636"},"relatedVulnerabilities":[{"id":"CVE-2026-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"urls":["https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-17","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gc62-2v5p-qpmp","https://github.com/dlemstra/Magick.NET/releases/tag/14.11.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32636","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-32636"},"relatedVulnerabilities":[{"id":"CVE-2026-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"urls":["https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-17","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gc62-2v5p-qpmp","https://github.com/dlemstra/Magick.NET/releases/tag/14.11.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32636","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-32636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-32636"},"relatedVulnerabilities":[{"id":"CVE-2026-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32636","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-32636","date":"2026-10-08","epss":0.00609,"percentile":0.4754}],"urls":["https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-17","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gc62-2v5p-qpmp","https://github.com/dlemstra/Magick.NET/releases/tag/14.11.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32636","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a single zero byte. Versions 7.1.2-17 and 6.9.13-42 fix the issue."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-69204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69204","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"risk":0.3005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69204"},"relatedVulnerabilities":[{"id":"CVE-2025-69204","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hrh7-j8q2-4qcw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69204","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69204","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"risk":0.3005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69204"},"relatedVulnerabilities":[{"id":"CVE-2025-69204","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hrh7-j8q2-4qcw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69204","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69204","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"risk":0.3005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69204"},"relatedVulnerabilities":[{"id":"CVE-2025-69204","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hrh7-j8q2-4qcw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69204","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69204","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"risk":0.3005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69204"},"relatedVulnerabilities":[{"id":"CVE-2025-69204","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hrh7-j8q2-4qcw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69204","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69204","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69204","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"risk":0.3005,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69204"},"relatedVulnerabilities":[{"id":"CVE-2025-69204","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69204","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-69204","date":"2026-10-08","epss":0.00601,"percentile":0.47136}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hrh7-j8q2-4qcw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69204","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33900","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33900","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"risk":0.3,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33900"},"relatedVulnerabilities":[{"id":"CVE-2026-33900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/d27b840a61b322419a66d0d192ff56d52498148d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v67w-737x-v2c9","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33900","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33900","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33900","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"risk":0.3,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33900"},"relatedVulnerabilities":[{"id":"CVE-2026-33900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/d27b840a61b322419a66d0d192ff56d52498148d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v67w-737x-v2c9","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33900","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33900","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33900","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"risk":0.3,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33900"},"relatedVulnerabilities":[{"id":"CVE-2026-33900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/d27b840a61b322419a66d0d192ff56d52498148d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v67w-737x-v2c9","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33900","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33900","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33900","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"risk":0.3,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33900"},"relatedVulnerabilities":[{"id":"CVE-2026-33900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/d27b840a61b322419a66d0d192ff56d52498148d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v67w-737x-v2c9","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33900","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33900","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33900","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"risk":0.3,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33900"},"relatedVulnerabilities":[{"id":"CVE-2026-33900","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33900","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33900","date":"2026-10-08","epss":0.006,"percentile":0.47092}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/d27b840a61b322419a66d0d192ff56d52498148d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v67w-737x-v2c9","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33900","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28693","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28693","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"risk":0.295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28693"},"relatedVulnerabilities":[{"id":"CVE-2026-28693","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28693","https://bugzilla.redhat.com/show_bug.cgi?id=2445888","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28693.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28693","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28693","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28693","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"risk":0.295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28693"},"relatedVulnerabilities":[{"id":"CVE-2026-28693","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28693","https://bugzilla.redhat.com/show_bug.cgi?id=2445888","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28693.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28693","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28693","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28693","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"risk":0.295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28693"},"relatedVulnerabilities":[{"id":"CVE-2026-28693","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28693","https://bugzilla.redhat.com/show_bug.cgi?id=2445888","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28693.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28693","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28693","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28693","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"risk":0.295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28693"},"relatedVulnerabilities":[{"id":"CVE-2026-28693","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28693","https://bugzilla.redhat.com/show_bug.cgi?id=2445888","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28693.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28693","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28693","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28693","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"risk":0.295,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28693"},"relatedVulnerabilities":[{"id":"CVE-2026-28693","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28693","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-28693","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-28693","date":"2026-10-08","epss":0.0059,"percentile":0.46559}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hffp-q43q-qq76","https://access.redhat.com/errata/RHSA-2026:6713","https://access.redhat.com/security/cve/CVE-2026-28693","https://bugzilla.redhat.com/show_bug.cgi?id=2445888","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28693.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28693","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, an integer overflow in DIB coder can result in out of bounds read or write. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"57ae2119a8593e71","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/ubuntu/libopenjp2-7@2.5.0-2ubuntu0.5?arch=amd64&distro=ubuntu-24.04&upstream=openjpeg2","type":"deb","version":"2.5.0-2ubuntu0.5","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openjpeg2","version":"2.5.0-2ubuntu0.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2023-39329","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"risk":0.294,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-39329"},"relatedVulnerabilities":[{"id":"CVE-2023-39329","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816","https://github.com/uclouvain/openjpeg/issues/1474"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4012","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4012","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"risk":0.290975,"urls":["https://go.dev/cl/709855","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75672","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-58186","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58186","date":"2026-10-08","epss":0.00565,"percentile":0.45157}],"urls":["https://go.dev/cl/709855","https://go.dev/issue/75672","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4012","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58186","description":"Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as \"a=;\", an attacker can make an HTTP server allocate a large amount of structs, causing large memory consumption."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-43965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-43965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"risk":0.2885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-43965"},"relatedVulnerabilities":[{"id":"CVE-2025-43965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/bac413a26073923d3ffb258adaab07fb3fe8fdc9","https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-44---2025-02-22","https://lists.debian.org/debian-lts-announce/2025/04/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-43965","description":"In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-43965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-43965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"risk":0.2885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-43965"},"relatedVulnerabilities":[{"id":"CVE-2025-43965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/bac413a26073923d3ffb258adaab07fb3fe8fdc9","https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-44---2025-02-22","https://lists.debian.org/debian-lts-announce/2025/04/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-43965","description":"In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-43965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-43965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"risk":0.2885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-43965"},"relatedVulnerabilities":[{"id":"CVE-2025-43965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/bac413a26073923d3ffb258adaab07fb3fe8fdc9","https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-44---2025-02-22","https://lists.debian.org/debian-lts-announce/2025/04/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-43965","description":"In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-43965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-43965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"risk":0.2885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-43965"},"relatedVulnerabilities":[{"id":"CVE-2025-43965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/bac413a26073923d3ffb258adaab07fb3fe8fdc9","https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-44---2025-02-22","https://lists.debian.org/debian-lts-announce/2025/04/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-43965","description":"In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-43965","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-43965","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"risk":0.2885,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-43965"},"relatedVulnerabilities":[{"id":"CVE-2025-43965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-43965","cwe":"CWE-131","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-43965","date":"2026-10-08","epss":0.00577,"percentile":0.45788}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/bac413a26073923d3ffb258adaab07fb3fe8fdc9","https://github.com/ImageMagick/Website/blob/main/ChangeLog.md#711-44---2025-02-22","https://lists.debian.org/debian-lts-announce/2025/04/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-43965","description":"In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4011","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4011","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/cl/709856","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75671","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2025-58185","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58185","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58185","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709856","https://go.dev/issue/75671","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4011","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58185","description":"Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4015","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4015","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"risk":0.28634,"urls":["https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709859","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61724","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61724","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61724","date":"2026-10-08","epss":0.00556,"percentile":0.44609}],"urls":["https://go.dev/cl/709859","https://go.dev/issue/75716","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4015","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61724","description":"The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4013","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4013","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"risk":0.28575,"urls":["https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709853","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method.\n\nThis affects programs which validate arbitrary certificate chains."},"relatedVulnerabilities":[{"id":"CVE-2025-58188","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58188","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58188","date":"2026-10-08","epss":0.00381,"percentile":0.30022}],"urls":["https://go.dev/cl/709853","https://go.dev/issue/75675","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4013","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58188","description":"Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arbitrary certificate chains."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25798","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25798","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"risk":0.28500000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25798"},"relatedVulnerabilities":[{"id":"CVE-2026-25798","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p863-5fgm-rgq4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25798","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image file, resulting in denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25798","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25798","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"risk":0.28500000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25798"},"relatedVulnerabilities":[{"id":"CVE-2026-25798","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p863-5fgm-rgq4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25798","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image file, resulting in denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25798","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25798","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"risk":0.28500000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25798"},"relatedVulnerabilities":[{"id":"CVE-2026-25798","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p863-5fgm-rgq4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25798","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image file, resulting in denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25798","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25798","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"risk":0.28500000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25798"},"relatedVulnerabilities":[{"id":"CVE-2026-25798","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p863-5fgm-rgq4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25798","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image file, resulting in denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25798","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25798","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"risk":0.28500000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25798"},"relatedVulnerabilities":[{"id":"CVE-2026-25798","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25798","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25798","date":"2026-10-08","epss":0.0057,"percentile":0.45445}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p863-5fgm-rgq4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25798","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplying a crafted image file, resulting in denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.17.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qv6h-rv94-w285","versionConstraint":"<6.17.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-qv6h-rv94-w285","fix":{"state":"fixed","versions":["6.17.0"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.17.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102993","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102993","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102993","date":"2026-10-08","epss":0.0035,"percentile":0.26599}],"risk":0.2835,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285","https://nvd.nist.gov/vuln/detail/CVE-2026-102993","https://github.com/py-pdf/pypdf/pull/4047","https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163","https://github.com/py-pdf/pypdf/releases/tag/6.17.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qv6h-rv94-w285","description":"pypdf: Possible large memory usage when retrieving Roman page labels"},"relatedVulnerabilities":[{"id":"CVE-2026-102993","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102993","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102993","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102993","date":"2026-10-08","epss":0.0035,"percentile":0.26599}],"urls":["https://github.com/py-pdf/pypdf/commit/89db7c4fe9315ecc964bfdf05a4e8c4b94175163","https://github.com/py-pdf/pypdf/pull/4047","https://github.com/py-pdf/pypdf/releases/tag/6.17.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102993","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.18.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jw7q-gvrg-4vj3","versionConstraint":"<6.18.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-jw7q-gvrg-4vj3","fix":{"state":"fixed","versions":["6.18.1"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.18.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102997","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102997","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102997","date":"2026-10-08","epss":0.00345,"percentile":0.25917}],"risk":0.27945,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-jw7q-gvrg-4vj3","https://nvd.nist.gov/vuln/detail/CVE-2026-102997","https://github.com/py-pdf/pypdf/pull/4073","https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79","https://github.com/py-pdf/pypdf/releases/tag/6.18.1"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jw7q-gvrg-4vj3","description":"pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)"},"relatedVulnerabilities":[{"id":"CVE-2026-102997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102997","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102997","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102997","date":"2026-10-08","epss":0.00345,"percentile":0.25917}],"urls":["https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79","https://github.com/py-pdf/pypdf/pull/4073","https://github.com/py-pdf/pypdf/releases/tag/6.18.1","https://github.com/py-pdf/pypdf/security/advisories/GHSA-jw7q-gvrg-4vj3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102997","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.18.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fp3h-c4fm-7vvf","versionConstraint":"<6.18.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-fp3h-c4fm-7vvf","fix":{"state":"fixed","versions":["6.18.1"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.18.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102995","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102995","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"risk":0.27945,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3h-c4fm-7vvf","https://nvd.nist.gov/vuln/detail/CVE-2026-102995","https://github.com/py-pdf/pypdf/pull/4071","https://github.com/py-pdf/pypdf/commit/319d0b823ce2c311a2435e9fd93c13994d32bb51","https://github.com/py-pdf/pypdf/releases/tag/6.18.1"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fp3h-c4fm-7vvf","description":"pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)"},"relatedVulnerabilities":[{"id":"CVE-2026-102995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102995","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102995","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"urls":["https://github.com/py-pdf/pypdf/commit/319d0b823ce2c311a2435e9fd93c13994d32bb51","https://github.com/py-pdf/pypdf/pull/4071","https://github.com/py-pdf/pypdf/releases/tag/6.18.1","https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3h-c4fm-7vvf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102995","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.18.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g9cg-prrw-2r8q","versionConstraint":"<6.18.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-g9cg-prrw-2r8q","fix":{"state":"fixed","versions":["6.18.1"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.18.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102996","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102996","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"risk":0.27945,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q","https://nvd.nist.gov/vuln/detail/CVE-2026-102996","https://github.com/py-pdf/pypdf/pull/4072","https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5","https://github.com/py-pdf/pypdf/releases/tag/6.18.1"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g9cg-prrw-2r8q","description":"pypdf: Possible large memory usage when parsing font data"},"relatedVulnerabilities":[{"id":"CVE-2026-102996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102996","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102996","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"urls":["https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5","https://github.com/py-pdf/pypdf/pull/4072","https://github.com/py-pdf/pypdf/releases/tag/6.18.1","https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102996","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.19.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v247-6f48-mgcj","versionConstraint":"<6.19.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-v247-6f48-mgcj","fix":{"state":"fixed","versions":["6.19.0"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.19.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102999","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102999","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102999","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"risk":0.27945,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj","https://nvd.nist.gov/vuln/detail/CVE-2026-102999","https://github.com/py-pdf/pypdf/pull/4081","https://github.com/py-pdf/pypdf/commit/6b10556d13609a68f9ed18bb29fdd8bba88eb2c3","https://github.com/py-pdf/pypdf/releases/tag/6.19.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v247-6f48-mgcj","description":"pypdf: Possible long runtimes with large amount of embedded files"},"relatedVulnerabilities":[{"id":"CVE-2026-102999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102999","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102999","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102999","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"urls":["https://github.com/py-pdf/pypdf/commit/6b10556d13609a68f9ed18bb29fdd8bba88eb2c3","https://github.com/py-pdf/pypdf/pull/4081","https://github.com/py-pdf/pypdf/releases/tag/6.19.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-v247-6f48-mgcj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102999","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.19.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w23x-9jrw-r45c","versionConstraint":"<6.19.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-w23x-9jrw-r45c","fix":{"state":"fixed","versions":["6.19.0"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.19.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103000","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-103000","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"risk":0.27945,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-w23x-9jrw-r45c","https://nvd.nist.gov/vuln/detail/CVE-2026-103000","https://github.com/py-pdf/pypdf/pull/4096","https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a","https://github.com/py-pdf/pypdf/releases/tag/6.19.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w23x-9jrw-r45c","description":"pypdf: Possible large memory usage when retrieving alphabetical page labels"},"relatedVulnerabilities":[{"id":"CVE-2026-103000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103000","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-103000","date":"2026-10-08","epss":0.00345,"percentile":0.25916}],"urls":["https://github.com/py-pdf/pypdf/commit/0d8b5a8832cde1ba308b5c27567b879b7b7eed4a","https://github.com/py-pdf/pypdf/pull/4096","https://github.com/py-pdf/pypdf/releases/tag/6.19.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-w23x-9jrw-r45c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103000","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.18.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jq2-8x83-x246","versionConstraint":"<6.18.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-5jq2-8x83-x246","fix":{"state":"fixed","versions":["6.18.0"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.18.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102994","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102994","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102994","date":"2026-10-08","epss":0.00345,"percentile":0.25915}],"risk":0.27945,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-5jq2-8x83-x246","https://nvd.nist.gov/vuln/detail/CVE-2026-102994","https://github.com/py-pdf/pypdf/pull/4055","https://github.com/py-pdf/pypdf/commit/82501d2993c6387833c4949d205caeb188f8bb9e","https://github.com/py-pdf/pypdf/releases/tag/6.18.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jq2-8x83-x246","description":"pypdf: Possible long runtimes/large memory usage when parsing indirect objects"},"relatedVulnerabilities":[{"id":"CVE-2026-102994","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102994","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102994","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102994","date":"2026-10-08","epss":0.00345,"percentile":0.25915}],"urls":["https://github.com/py-pdf/pypdf/commit/82501d2993c6387833c4949d205caeb188f8bb9e","https://github.com/py-pdf/pypdf/pull/4055","https://github.com/py-pdf/pypdf/releases/tag/6.18.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-5jq2-8x83-x246"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102994","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0."}]},{"artifact":{"id":"cc433389210804dd","cpes":["cpe:2.3:a:pypdf_project:pypdf:6.10.2:*:*:*:*:*:*:*"],"name":"pypdf","purl":"pkg:pypi/pypdf@6.10.2","type":"python","version":"6.10.2","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/pypdf-6.10.2.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.19.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-php9-fj8v-98fj","versionConstraint":"<6.19.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"pypdf","version":"6.10.2"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-php9-fj8v-98fj","fix":{"state":"fixed","versions":["6.19.0"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.19.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102998","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102998","date":"2026-10-08","epss":0.00345,"percentile":0.25915}],"risk":0.27945,"urls":["https://github.com/py-pdf/pypdf/security/advisories/GHSA-php9-fj8v-98fj","https://nvd.nist.gov/vuln/detail/CVE-2026-102998","https://github.com/py-pdf/pypdf/pull/4087","https://github.com/py-pdf/pypdf/commit/959467a9b95be83e2dc5ae873ece5f371263ede7","https://github.com/py-pdf/pypdf/releases/tag/6.19.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-php9-fj8v-98fj","description":"pypdf: Possible long runtimes when generating appearance streams"},"relatedVulnerabilities":[{"id":"CVE-2026-102998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102998","cwe":"CWE-400","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102998","date":"2026-10-08","epss":0.00345,"percentile":0.25915}],"urls":["https://github.com/py-pdf/pypdf/commit/959467a9b95be83e2dc5ae873ece5f371263ede7","https://github.com/py-pdf/pypdf/pull/4087","https://github.com/py-pdf/pypdf/releases/tag/6.19.0","https://github.com/py-pdf/pypdf/security/advisories/GHSA-php9-fj8v-98fj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102998","description":"pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3849","versionConstraint":"<1.23.12||>=1.24.0,<1.24.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3849","fix":{"state":"fixed","versions":["1.23.12","1.24.6"],"available":[{"date":"2025-08-06","kind":"release","version":"1.23.12"},{"date":"2025-08-06","kind":"release","version":"1.24.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47907","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47907","date":"2026-10-08","epss":0.00383,"percentile":0.30221}],"risk":0.277675,"urls":["https://go.dev/issue/74831","https://groups.google.com/g/golang-announce/c/x5MKroML2yM"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/693735","description":"Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error."},"relatedVulnerabilities":[{"id":"CVE-2025-47907","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47907","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47907","date":"2026-10-08","epss":0.00383,"percentile":0.30221}],"urls":["https://go.dev/cl/693735","https://go.dev/issue/74831","https://groups.google.com/g/golang-announce/c/x5MKroML2yM","https://pkg.go.dev/vuln/GO-2025-3849","http://www.openwall.com/lists/oss-security/2025/08/06/1"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47907","description":"Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-61861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-61861","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"risk":0.27699999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-61861"},"relatedVulnerabilities":[{"id":"CVE-2026-61861","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2","https://www.vulncheck.com/advisories/imagemagick-before-26-use-after-free-in-formatmagickcaption"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61861","description":"ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-61861","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"risk":0.27699999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-61861"},"relatedVulnerabilities":[{"id":"CVE-2026-61861","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2","https://www.vulncheck.com/advisories/imagemagick-before-26-use-after-free-in-formatmagickcaption"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61861","description":"ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-61861","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"risk":0.27699999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-61861"},"relatedVulnerabilities":[{"id":"CVE-2026-61861","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2","https://www.vulncheck.com/advisories/imagemagick-before-26-use-after-free-in-formatmagickcaption"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61861","description":"ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-61861","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"risk":0.27699999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-61861"},"relatedVulnerabilities":[{"id":"CVE-2026-61861","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2","https://www.vulncheck.com/advisories/imagemagick-before-26-use-after-free-in-formatmagickcaption"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61861","description":"ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61861","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-61861","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"risk":0.27699999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-61861"},"relatedVulnerabilities":[{"id":"CVE-2026-61861","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61861","cwe":"CWE-416","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-61861","date":"2026-10-08","epss":0.00554,"percentile":0.44527}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2","https://www.vulncheck.com/advisories/imagemagick-before-26-use-after-free-in-formatmagickcaption"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61861","description":"ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling pointer to reference freed memory, potentially enabling denial of service or code execution."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25989","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25989","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"risk":0.27599999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25989"},"relatedVulnerabilities":[{"id":"CVE-2026-25989","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7355-pwx2-pm84"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25989","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25989","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25989","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"risk":0.27599999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25989"},"relatedVulnerabilities":[{"id":"CVE-2026-25989","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7355-pwx2-pm84"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25989","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25989","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25989","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"risk":0.27599999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25989"},"relatedVulnerabilities":[{"id":"CVE-2026-25989","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7355-pwx2-pm84"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25989","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25989","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25989","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"risk":0.27599999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25989"},"relatedVulnerabilities":[{"id":"CVE-2026-25989","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7355-pwx2-pm84"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25989","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25989","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25989","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"risk":0.27599999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25989"},"relatedVulnerabilities":[{"id":"CVE-2026-25989","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25989","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-681","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25989","cwe":"CWE-193","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25989","date":"2026-10-08","epss":0.00552,"percentile":0.44383}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7355-pwx2-pm84"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25989","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.2745,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77214"},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4946","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4946","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"risk":0.26625,"urls":["https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758061","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.\n\nThis only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},"relatedVulnerabilities":[{"id":"CVE-2026-32281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"urls":["https://go.dev/cl/758061","https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4946"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.22.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-3373","versionConstraint":"<1.22.11||>=1.23.0-0,<1.23.5||>=1.24.0-0,<1.24.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-3373","fix":{"state":"fixed","versions":["1.22.11","1.23.5","1.24.0-rc.2"],"available":[{"date":"2025-01-16","kind":"release","version":"1.22.11"},{"date":"2025-01-16","kind":"release","version":"1.23.5"},{"date":"2025-01-16","kind":"release","version":"1.24.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45341","date":"2026-10-08","epss":0.00476,"percentile":0.39127}],"risk":0.26417999999999997,"urls":["https://go.dev/issue/71156","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/643099","description":"A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain.\n\nCertificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs."},"relatedVulnerabilities":[{"id":"CVE-2024-45341","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45341","date":"2026-10-08","epss":0.00476,"percentile":0.39127}],"urls":["https://go.dev/cl/643099","https://go.dev/issue/71156","https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ","https://groups.google.com/g/golang-dev/c/bG8cv1muIBM/m/G461hA6lCgAJ","https://pkg.go.dev/vuln/GO-2025-3373","https://security.netapp.com/advisory/ntap-20250221-0004/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-45341","description":"A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33899","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33899","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"risk":0.262,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33899"},"relatedVulnerabilities":[{"id":"CVE-2026-33899","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae679e2fd19ec656bfab9f822ae4cf06bf91604d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cr67-pvmx-2pp2","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33899","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33899","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33899","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"risk":0.262,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33899"},"relatedVulnerabilities":[{"id":"CVE-2026-33899","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae679e2fd19ec656bfab9f822ae4cf06bf91604d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cr67-pvmx-2pp2","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33899","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33899","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33899","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"risk":0.262,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33899"},"relatedVulnerabilities":[{"id":"CVE-2026-33899","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae679e2fd19ec656bfab9f822ae4cf06bf91604d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cr67-pvmx-2pp2","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33899","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33899","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33899","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"risk":0.262,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33899"},"relatedVulnerabilities":[{"id":"CVE-2026-33899","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae679e2fd19ec656bfab9f822ae4cf06bf91604d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cr67-pvmx-2pp2","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33899","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33899","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33899","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"risk":0.262,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33899"},"relatedVulnerabilities":[{"id":"CVE-2026-33899","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33899","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33899","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33899","date":"2026-10-08","epss":0.00524,"percentile":0.42612}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/ae679e2fd19ec656bfab9f822ae4cf06bf91604d","https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-19","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cr67-pvmx-2pp2","https://github.com/dlemstra/Magick.NET/releases/tag/14.12.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33899","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-53019","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53019","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"risk":0.2595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53019"},"relatedVulnerabilities":[{"id":"CVE-2025-53019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cfh4-9f7v-fhrc","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53019","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53019","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53019","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"risk":0.2595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53019"},"relatedVulnerabilities":[{"id":"CVE-2025-53019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cfh4-9f7v-fhrc","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53019","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53019","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53019","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"risk":0.2595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53019"},"relatedVulnerabilities":[{"id":"CVE-2025-53019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cfh4-9f7v-fhrc","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53019","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53019","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53019","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"risk":0.2595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53019"},"relatedVulnerabilities":[{"id":"CVE-2025-53019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cfh4-9f7v-fhrc","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53019","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-53019","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-53019","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"risk":0.2595,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-53019"},"relatedVulnerabilities":[{"id":"CVE-2025-53019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-53019","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-53019","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-53019","date":"2026-10-08","epss":0.00519,"percentile":0.423}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cfh4-9f7v-fhrc","https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-53019","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in a filename template causes a memory leak. Versions 7.1.2-0 and 6.9.13-26 fix the issue."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"risk":0.2575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25983"},"relatedVulnerabilities":[{"id":"CVE-2026-25983","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwqw-2x5x-w566"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"risk":0.2575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25983"},"relatedVulnerabilities":[{"id":"CVE-2026-25983","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwqw-2x5x-w566"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"risk":0.2575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25983"},"relatedVulnerabilities":[{"id":"CVE-2026-25983","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwqw-2x5x-w566"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"risk":0.2575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25983"},"relatedVulnerabilities":[{"id":"CVE-2026-25983","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwqw-2x5x-w566"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"risk":0.2575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25983"},"relatedVulnerabilities":[{"id":"CVE-2026-25983","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25983","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25983","date":"2026-10-08","epss":0.00515,"percentile":0.42039}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fwqw-2x5x-w566"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted MSL script triggers a heap-use-after-free. The operation element handler replaces and frees the image while the parser continues reading from it, leading to a UAF in ReadBlobString during further parsing. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25986","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25986","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"risk":0.2565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25986"},"relatedVulnerabilities":[{"id":"CVE-2026-25986","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mqfc-82jx-3mr2"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25986","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25986","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25986","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"risk":0.2565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25986"},"relatedVulnerabilities":[{"id":"CVE-2026-25986","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mqfc-82jx-3mr2"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25986","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25986","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25986","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"risk":0.2565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25986"},"relatedVulnerabilities":[{"id":"CVE-2026-25986","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mqfc-82jx-3mr2"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25986","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25986","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25986","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"risk":0.2565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25986"},"relatedVulnerabilities":[{"id":"CVE-2026-25986","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mqfc-82jx-3mr2"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25986","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25986","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25986","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"risk":0.2565,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25986"},"relatedVulnerabilities":[{"id":"CVE-2026-25986","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25986","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25986","date":"2026-10-08","epss":0.00513,"percentile":0.41833}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mqfc-82jx-3mr2"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25986","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer overflow write vulnerability exists in ReadYUVImage() (coders/yuv.c) when processing malicious YUV 4:2:2 (NoInterlace) images. The pixel-pair loop writes one pixel beyond the allocated row buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66628","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"risk":0.255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66628"},"relatedVulnerabilities":[{"id":"CVE-2025-66628","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8","https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66628","description":"ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66628","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"risk":0.255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66628"},"relatedVulnerabilities":[{"id":"CVE-2025-66628","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8","https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66628","description":"ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66628","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"risk":0.255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66628"},"relatedVulnerabilities":[{"id":"CVE-2025-66628","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8","https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66628","description":"ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66628","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"risk":0.255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66628"},"relatedVulnerabilities":[{"id":"CVE-2025-66628","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8","https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66628","description":"ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66628","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66628","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"risk":0.255,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66628"},"relatedVulnerabilities":[{"id":"CVE-2025-66628","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66628","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66628","date":"2026-10-08","epss":0.0051,"percentile":0.41622}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8","https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66628","description":"ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25799","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25799","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"risk":0.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25799"},"relatedVulnerabilities":[{"id":"CVE-2026-25799","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-543g-8grm-9cw6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25799","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25799","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25799","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"risk":0.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25799"},"relatedVulnerabilities":[{"id":"CVE-2026-25799","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-543g-8grm-9cw6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25799","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25799","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25799","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"risk":0.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25799"},"relatedVulnerabilities":[{"id":"CVE-2026-25799","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-543g-8grm-9cw6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25799","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25799","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25799","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"risk":0.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25799"},"relatedVulnerabilities":[{"id":"CVE-2026-25799","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-543g-8grm-9cw6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25799","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25799","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25799","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"risk":0.245,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25799"},"relatedVulnerabilities":[{"id":"CVE-2026-25799","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25799","cwe":"CWE-369","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25799","date":"2026-10-08","epss":0.0049,"percentile":0.40176}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-543g-8grm-9cw6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25799","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57585","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57585","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57585","date":"2026-10-08","epss":0.00488,"percentile":0.40034}],"risk":0.244,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57585"},"relatedVulnerabilities":[{"id":"CVE-2026-57585","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57585","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57585","date":"2026-10-08","epss":0.00488,"percentile":0.40034}],"urls":["https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d","https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57585","description":"MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25970","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25970","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25970"},"relatedVulnerabilities":[{"id":"CVE-2026-25970","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xg29-8ghv-v4xr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25970","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25988","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25988"},"relatedVulnerabilities":[{"id":"CVE-2026-25988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-782x-jh29-9mf7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25988","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never freed on error, causing leaks. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25970","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25970","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25970"},"relatedVulnerabilities":[{"id":"CVE-2026-25970","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xg29-8ghv-v4xr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25970","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25988","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25988"},"relatedVulnerabilities":[{"id":"CVE-2026-25988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-782x-jh29-9mf7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25988","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never freed on error, causing leaks. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25970","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25970","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25970"},"relatedVulnerabilities":[{"id":"CVE-2026-25970","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xg29-8ghv-v4xr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25970","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25988","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25988"},"relatedVulnerabilities":[{"id":"CVE-2026-25988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-782x-jh29-9mf7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25988","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never freed on error, causing leaks. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25970","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25970","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25970"},"relatedVulnerabilities":[{"id":"CVE-2026-25970","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xg29-8ghv-v4xr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25970","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25988","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25988"},"relatedVulnerabilities":[{"id":"CVE-2026-25988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-782x-jh29-9mf7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25988","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never freed on error, causing leaks. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25970","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25970","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25970"},"relatedVulnerabilities":[{"id":"CVE-2026-25970","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25970","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25970","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-xg29-8ghv-v4xr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25970","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a signed integer overflow vulnerability in ImageMagick's SIXEL decoder allows an attacker to trigger memory corruption and denial of service when processing a maliciously crafted SIXEL image file. The vulnerability occurs during buffer reallocation operations where pointer arithmetic using signed 32-bit integers overflows. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25988","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"risk":0.2415,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25988"},"relatedVulnerabilities":[{"id":"CVE-2026-25988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25988","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25988","date":"2026-10-08","epss":0.00483,"percentile":0.39696}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-782x-jh29-9mf7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25988","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image is stored in the wrong slot and never freed on error, causing leaks. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4008","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4008","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/707776","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."},"relatedVulnerabilities":[{"id":"CVE-2025-58189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58189","cwe":"CWE-532","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-58189","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/707776","https://go.dev/issue/75652","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4008","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58189","description":"When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4010","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4010","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"risk":0.24101999999999998,"urls":["https://go.dev/cl/709857","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/75678","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."},"relatedVulnerabilities":[{"id":"CVE-2025-47912","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-47912","date":"2026-10-08","epss":0.00468,"percentile":0.38509}],"urls":["https://go.dev/cl/709857","https://go.dev/issue/75678","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4010","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47912","description":"The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. For example: \"http://[::1]/\". IPv4 addresses and hostnames must not appear within square brackets. Parse did not enforce this requirement."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-23952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23952"},"relatedVulnerabilities":[{"id":"CVE-2026-23952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5vx3-wx4q-6cj8","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23952","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23952"},"relatedVulnerabilities":[{"id":"CVE-2026-23952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5vx3-wx4q-6cj8","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23952","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23952"},"relatedVulnerabilities":[{"id":"CVE-2026-23952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5vx3-wx4q-6cj8","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23952","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23952"},"relatedVulnerabilities":[{"id":"CVE-2026-23952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5vx3-wx4q-6cj8","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23952","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-23952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-23952"},"relatedVulnerabilities":[{"id":"CVE-2026-23952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23952","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23952","date":"2026-10-08","epss":0.00478,"percentile":0.39288}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5vx3-wx4q-6cj8","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23952","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25795","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25795","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25795"},"relatedVulnerabilities":[{"id":"CVE-2026-25795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p33r-fqw2-rqmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25795","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, causing a NULL pointer dereference and crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25796"},"relatedVulnerabilities":[{"id":"CVE-2026-25796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g2pr-qxjg-7r2w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25796","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25795","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25795","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25795"},"relatedVulnerabilities":[{"id":"CVE-2026-25795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p33r-fqw2-rqmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25795","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, causing a NULL pointer dereference and crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25796"},"relatedVulnerabilities":[{"id":"CVE-2026-25796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g2pr-qxjg-7r2w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25796","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25795","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25795","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25795"},"relatedVulnerabilities":[{"id":"CVE-2026-25795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p33r-fqw2-rqmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25795","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, causing a NULL pointer dereference and crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25796"},"relatedVulnerabilities":[{"id":"CVE-2026-25796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g2pr-qxjg-7r2w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25796","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25795","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25795","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25795"},"relatedVulnerabilities":[{"id":"CVE-2026-25795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p33r-fqw2-rqmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25795","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, causing a NULL pointer dereference and crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25796"},"relatedVulnerabilities":[{"id":"CVE-2026-25796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g2pr-qxjg-7r2w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25796","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25795","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25795","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25795"},"relatedVulnerabilities":[{"id":"CVE-2026-25795","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25795","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25795","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-p33r-fqw2-rqmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25795","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, causing a NULL pointer dereference and crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"risk":0.23900000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25796"},"relatedVulnerabilities":[{"id":"CVE-2026-25796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25796","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25796","date":"2026-10-08","epss":0.00478,"percentile":0.39287}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-g2pr-qxjg-7r2w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25796","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite memory leak (~13.5KB+ per invocation) that can be exploited for denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25898","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25898","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25898"},"relatedVulnerabilities":[{"id":"CVE-2026-25898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vpxv-r9pg-7gpr"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25898","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25898","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25898","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25898"},"relatedVulnerabilities":[{"id":"CVE-2026-25898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vpxv-r9pg-7gpr"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25898","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25898","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25898","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25898"},"relatedVulnerabilities":[{"id":"CVE-2026-25898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vpxv-r9pg-7gpr"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25898","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25898","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25898","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25898"},"relatedVulnerabilities":[{"id":"CVE-2026-25898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vpxv-r9pg-7gpr"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25898","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25898","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25898","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25898"},"relatedVulnerabilities":[{"id":"CVE-2026-25898","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25898","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25898","date":"2026-10-08","epss":0.00471,"percentile":0.38737}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vpxv-r9pg-7gpr"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25898","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.21.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2024-2888","versionConstraint":"<1.21.11||>=1.22.0-0,<1.22.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2024-2888","fix":{"state":"fixed","versions":["1.21.11","1.22.4"],"available":[{"date":"2024-06-04","kind":"release","version":"1.21.11"},{"date":"2024-06-04","kind":"release","version":"1.22.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24789","date":"2026-10-08","epss":0.00446,"percentile":0.36799}],"risk":0.23415000000000002,"urls":["https://go.dev/issue/66869","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/585397","description":"The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors."},"relatedVulnerabilities":[{"id":"CVE-2024-24789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-24789","date":"2026-10-08","epss":0.00446,"percentile":0.36799}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/04/1","https://go.dev/cl/585397","https://go.dev/issue/66869","https://groups.google.com/g/golang-announce/c/XbxouI9gY7k/m/TuoGEhxIEwAJ","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5YAEIA6IUHUNGJ7AIXXPQT6D2GYENX7/","https://pkg.go.dev/vuln/GO-2024-2888","https://security.netapp.com/advisory/ntap-20250131-0008/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-24789","description":"The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25968","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25968","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"risk":0.233,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25968"},"relatedVulnerabilities":[{"id":"CVE-2026-25968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3mwp-xqp2-q6ph"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25968","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25968","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25968","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"risk":0.233,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25968"},"relatedVulnerabilities":[{"id":"CVE-2026-25968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3mwp-xqp2-q6ph"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25968","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25968","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25968","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"risk":0.233,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25968"},"relatedVulnerabilities":[{"id":"CVE-2026-25968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3mwp-xqp2-q6ph"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25968","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25968","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25968","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"risk":0.233,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25968"},"relatedVulnerabilities":[{"id":"CVE-2026-25968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3mwp-xqp2-q6ph"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25968","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25968","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25968","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"risk":0.233,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25968"},"relatedVulnerabilities":[{"id":"CVE-2026-25968","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25968","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25968","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25968","date":"2026-10-08","epss":0.00466,"percentile":0.38333}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3mwp-xqp2-q6ph"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25968","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8643","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8643","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-08","epss":0.00466,"percentile":0.38331}],"risk":0.233,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8643"},"relatedVulnerabilities":[{"id":"CVE-2026-8643","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-08","epss":0.00466,"percentile":0.38331}],"urls":["https://github.com/pypa/pip/pull/14000","https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/","http://www.openwall.com/lists/oss-security/2026/06/01/5","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:34456","https://access.redhat.com/errata/RHSA-2026:34739","https://access.redhat.com/errata/RHSA-2026:34740","https://access.redhat.com/errata/RHSA-2026:34741","https://access.redhat.com/errata/RHSA-2026:34748","https://access.redhat.com/errata/RHSA-2026:34749","https://access.redhat.com/errata/RHSA-2026:34750","https://access.redhat.com/errata/RHSA-2026:34752","https://access.redhat.com/errata/RHSA-2026:34756","https://access.redhat.com/errata/RHSA-2026:34758","https://access.redhat.com/errata/RHSA-2026:34760","https://access.redhat.com/errata/RHSA-2026:34765","https://access.redhat.com/errata/RHSA-2026:34772","https://access.redhat.com/errata/RHSA-2026:34773","https://access.redhat.com/errata/RHSA-2026:34774","https://access.redhat.com/errata/RHSA-2026:34775","https://access.redhat.com/errata/RHSA-2026:34776","https://access.redhat.com/errata/RHSA-2026:34777","https://access.redhat.com/errata/RHSA-2026:34778","https://access.redhat.com/errata/RHSA-2026:34780","https://access.redhat.com/errata/RHSA-2026:34891","https://access.redhat.com/errata/RHSA-2026:36193","https://access.redhat.com/errata/RHSA-2026:36315","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37283","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42144","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:50479","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:56347","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/security/cve/CVE-2026-8643","https://bugzilla.redhat.com/show_bug.cgi?id=2460927","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8643","description":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56368","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56368"},"relatedVulnerabilities":[{"id":"CVE-2026-56368","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56368","description":"ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56368","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56368"},"relatedVulnerabilities":[{"id":"CVE-2026-56368","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56368","description":"ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56368","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56368"},"relatedVulnerabilities":[{"id":"CVE-2026-56368","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56368","description":"ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56368","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56368"},"relatedVulnerabilities":[{"id":"CVE-2026-56368","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56368","description":"ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56368","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56368"},"relatedVulnerabilities":[{"id":"CVE-2026-56368","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56368","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56368","date":"2026-10-08","epss":0.0046,"percentile":0.37936}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wfx3-6g53-9fgc","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-raw-pixel-data-coders"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56368","description":"ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-26284","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26284","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26284"},"relatedVulnerabilities":[{"id":"CVE-2026-26284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wrhr-rf8j-r842"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26284","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26284","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26284","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26284"},"relatedVulnerabilities":[{"id":"CVE-2026-26284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wrhr-rf8j-r842"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26284","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26284","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26284","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26284"},"relatedVulnerabilities":[{"id":"CVE-2026-26284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wrhr-rf8j-r842"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26284","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26284","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26284","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26284"},"relatedVulnerabilities":[{"id":"CVE-2026-26284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wrhr-rf8j-r842"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26284","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26284","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26284","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"risk":0.22999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26284"},"relatedVulnerabilities":[{"id":"CVE-2026-26284","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26284","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26284","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26284","date":"2026-10-08","epss":0.0046,"percentile":0.37847}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wrhr-rf8j-r842"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26284","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huffman-coded data from PCD (Photo CD) files. The decoder contains an function that has an incorrect initialization that could cause an out of bounds read. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-24485","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24485","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"risk":0.2285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24485"},"relatedVulnerabilities":[{"id":"CVE-2026-24485","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24485","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24485","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24485","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"risk":0.2285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24485"},"relatedVulnerabilities":[{"id":"CVE-2026-24485","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24485","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24485","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24485","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"risk":0.2285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24485"},"relatedVulnerabilities":[{"id":"CVE-2026-24485","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24485","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24485","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24485","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"risk":0.2285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24485"},"relatedVulnerabilities":[{"id":"CVE-2026-24485","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24485","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24485","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24485","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"risk":0.2285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24485"},"relatedVulnerabilities":[{"id":"CVE-2026-24485","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24485","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24485","date":"2026-10-08","epss":0.00457,"percentile":0.37685}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/332c1566acc2de77857032d3c2504ead6210ff50","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pqgj-2p96-rx85","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24485","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"risk":0.2285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45409"},"relatedVulnerabilities":[{"id":"CVE-2026-45409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"urls":["https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409","description":"Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.2265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86421"},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.2265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86421"},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.2265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86421"},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.2265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86421"},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86421","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86421","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"risk":0.2265,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86421"},"relatedVulnerabilities":[{"id":"CVE-2026-86421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86421","cwe":"CWE-400","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-86421","date":"2026-10-08","epss":0.00453,"percentile":0.37378}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x","https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-memory-leak-via-msl-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86421","description":"ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25987","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25987","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"risk":0.2215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25987"},"relatedVulnerabilities":[{"id":"CVE-2026-25987","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-42p5-62qq-mmh7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25987","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP files, potentially leading to crashes or unintended memory disclosure during image decoding. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25987","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25987","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"risk":0.2215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25987"},"relatedVulnerabilities":[{"id":"CVE-2026-25987","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-42p5-62qq-mmh7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25987","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP files, potentially leading to crashes or unintended memory disclosure during image decoding. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25987","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25987","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"risk":0.2215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25987"},"relatedVulnerabilities":[{"id":"CVE-2026-25987","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-42p5-62qq-mmh7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25987","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP files, potentially leading to crashes or unintended memory disclosure during image decoding. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25987","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25987","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"risk":0.2215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25987"},"relatedVulnerabilities":[{"id":"CVE-2026-25987","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-42p5-62qq-mmh7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25987","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP files, potentially leading to crashes or unintended memory disclosure during image decoding. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25987","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25987","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"risk":0.2215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25987"},"relatedVulnerabilities":[{"id":"CVE-2026-25987","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25987","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25987","date":"2026-10-08","epss":0.00443,"percentile":0.36464}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-42p5-62qq-mmh7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25987","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image decoder when processing crafted MAP files, potentially leading to crashes or unintended memory disclosure during image decoding. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56371","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"risk":0.22,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56371"},"relatedVulnerabilities":[{"id":"CVE-2026-56371","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3q5f-gmjc-38r8","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-txt-file-processing-via-texture-attribute"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56371","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56371","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"risk":0.22,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56371"},"relatedVulnerabilities":[{"id":"CVE-2026-56371","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3q5f-gmjc-38r8","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-txt-file-processing-via-texture-attribute"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56371","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56371","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"risk":0.22,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56371"},"relatedVulnerabilities":[{"id":"CVE-2026-56371","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3q5f-gmjc-38r8","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-txt-file-processing-via-texture-attribute"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56371","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56371","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"risk":0.22,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56371"},"relatedVulnerabilities":[{"id":"CVE-2026-56371","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3q5f-gmjc-38r8","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-txt-file-processing-via-texture-attribute"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56371","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56371","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"risk":0.22,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56371"},"relatedVulnerabilities":[{"id":"CVE-2026-56371","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56371","cwe":"CWE-401","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56371","date":"2026-10-08","epss":0.0044,"percentile":0.3619}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3q5f-gmjc-38r8","https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-txt-file-processing-via-texture-attribute"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56371","description":"ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4980","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4980","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"risk":0.21811499999999998,"urls":["https://go.dev/cl/771180","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78981","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."},"relatedVulnerabilities":[{"id":"CVE-2026-39826","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"urls":["https://go.dev/cl/771180","https://go.dev/issue/78981","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4980"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39826","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."}]},{"artifact":{"id":"ae36307ca07e59fc","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.1\\+git230720-4ubuntu2.5:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/ubuntu/libtiff6@4.5.1%2Bgit230720-4ubuntu2.5?arch=amd64&distro=ubuntu-24.04&upstream=tiff","type":"deb","version":"4.5.1+git230720-4ubuntu2.5","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12912","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tiff","version":"4.5.1+git230720-4ubuntu2.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12912","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"risk":0.21649999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12912"},"relatedVulnerabilities":[{"id":"CVE-2026-12912","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"urls":["https://access.redhat.com/errata/RHSA-2026:34890","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:42668","https://access.redhat.com/errata/RHSA-2026:47183","https://access.redhat.com/errata/RHSA-2026:47184","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:50774","https://access.redhat.com/errata/RHSA-2026:54638","https://access.redhat.com/errata/RHSA-2026:54640","https://access.redhat.com/errata/RHSA-2026:54642","https://access.redhat.com/errata/RHSA-2026:58545","https://access.redhat.com/errata/RHSA-2026:58553","https://access.redhat.com/errata/RHSA-2026:58554","https://access.redhat.com/errata/RHSA-2026:58556","https://access.redhat.com/errata/RHSA-2026:61657","https://access.redhat.com/errata/RHSA-2026:69292","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-12912","https://bugzilla.redhat.com/show_bug.cgi?id=2492871","https://gitlab.com/libtiff/libtiff/-/merge_requests/873","https://gitlab.com/libtiff/libtiff/-/work_items/824","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4976","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4976","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"risk":0.212695,"urls":["https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/770541","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions.\n\nWhen used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function.\n\nFor example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."},"relatedVulnerabilities":[{"id":"CVE-2026-39825","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"urls":["https://go.dev/cl/770541","https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4976"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39825","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"85460752c3000dd1","cpes":["cpe:2.3:a:libxslt1.1:libxslt1.1:1.1.39-0exp1ubuntu0.24.04.3:*:*:*:*:*:*:*"],"name":"libxslt1.1","purl":"pkg:deb/ubuntu/libxslt1.1@1.1.39-0exp1ubuntu0.24.04.3?arch=amd64&distro=ubuntu-24.04&upstream=libxslt","type":"deb","version":"1.1.39-0exp1ubuntu0.24.04.3","language":"","licenses":["sha256:4b82c8dd6e55001a5921bea1d6db20be5c51e5976d892e870324026c23f37b6f"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxslt1.1/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libxslt1.1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libxslt1.1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libxslt"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-7425","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxslt","version":"1.1.39-0exp1ubuntu0.24.04.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-7425","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-7425","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7425","date":"2026-10-08","epss":0.00424,"percentile":0.34716}],"risk":0.212,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-7425"},"relatedVulnerabilities":[{"id":"CVE-2025-7425","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7425","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7425","date":"2026-10-08","epss":0.00424,"percentile":0.34716}],"urls":["https://access.redhat.com/errata/RHBA-2025:12345","https://access.redhat.com/errata/RHSA-2025:12447","https://access.redhat.com/errata/RHSA-2025:12450","https://access.redhat.com/errata/RHSA-2025:13267","https://access.redhat.com/errata/RHSA-2025:13308","https://access.redhat.com/errata/RHSA-2025:13309","https://access.redhat.com/errata/RHSA-2025:13310","https://access.redhat.com/errata/RHSA-2025:13311","https://access.redhat.com/errata/RHSA-2025:13312","https://access.redhat.com/errata/RHSA-2025:13313","https://access.redhat.com/errata/RHSA-2025:13314","https://access.redhat.com/errata/RHSA-2025:13335","https://access.redhat.com/errata/RHSA-2025:13464","https://access.redhat.com/errata/RHSA-2025:13622","https://access.redhat.com/errata/RHSA-2025:14059","https://access.redhat.com/errata/RHSA-2025:14396","https://access.redhat.com/errata/RHSA-2025:14818","https://access.redhat.com/errata/RHSA-2025:14819","https://access.redhat.com/errata/RHSA-2025:14853","https://access.redhat.com/errata/RHSA-2025:14858","https://access.redhat.com/errata/RHSA-2025:15308","https://access.redhat.com/errata/RHSA-2025:15672","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:21913","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/errata/RHSA-2026:11503","https://access.redhat.com/security/cve/CVE-2025-7425","https://bugzilla.redhat.com/show_bug.cgi?id=2379274","https://gitlab.gnome.org/GNOME/libxslt/-/issues/140","http://seclists.org/fulldisclosure/2025/Aug/0","http://seclists.org/fulldisclosure/2025/Jul/30","http://seclists.org/fulldisclosure/2025/Jul/32","http://seclists.org/fulldisclosure/2025/Jul/35","http://seclists.org/fulldisclosure/2025/Jul/37","http://www.openwall.com/lists/oss-security/2025/07/11/2","https://lists.debian.org/debian-lts-announce/2025/09/msg00035.html","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7425","description":"A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25638","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25638","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25638"},"relatedVulnerabilities":[{"id":"CVE-2026-25638","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gxcx-qjqp-8vjw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25638","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns early without releasing these allocated resources. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-26983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26983"},"relatedVulnerabilities":[{"id":"CVE-2026-26983","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w8mw-frc6-r7m8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28687","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28687","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28687"},"relatedVulnerabilities":[{"id":"CVE-2026-28687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28687","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25638","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25638","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25638"},"relatedVulnerabilities":[{"id":"CVE-2026-25638","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gxcx-qjqp-8vjw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25638","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns early without releasing these allocated resources. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26983"},"relatedVulnerabilities":[{"id":"CVE-2026-26983","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w8mw-frc6-r7m8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28687","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28687","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28687"},"relatedVulnerabilities":[{"id":"CVE-2026-28687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28687","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25638","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25638","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25638"},"relatedVulnerabilities":[{"id":"CVE-2026-25638","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gxcx-qjqp-8vjw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25638","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns early without releasing these allocated resources. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26983"},"relatedVulnerabilities":[{"id":"CVE-2026-26983","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w8mw-frc6-r7m8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28687","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28687","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28687"},"relatedVulnerabilities":[{"id":"CVE-2026-28687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28687","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25638","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25638","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25638"},"relatedVulnerabilities":[{"id":"CVE-2026-25638","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gxcx-qjqp-8vjw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25638","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns early without releasing these allocated resources. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26983"},"relatedVulnerabilities":[{"id":"CVE-2026-26983","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w8mw-frc6-r7m8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28687","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28687","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28687"},"relatedVulnerabilities":[{"id":"CVE-2026-28687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28687","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25638","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25638","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25638"},"relatedVulnerabilities":[{"id":"CVE-2026-25638","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25638","cwe":"CWE-401","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25638","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gxcx-qjqp-8vjw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25638","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns early without releasing these allocated resources. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-26983","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-26983","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-26983"},"relatedVulnerabilities":[{"id":"CVE-2026-26983","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-26983","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-26983","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-26983","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w8mw-frc6-r7m8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-26983","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28687","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28687","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28687"},"relatedVulnerabilities":[{"id":"CVE-2026-28687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28687","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28687","date":"2026-10-08","epss":0.00418,"percentile":0.34066}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fpvf-frm6-625q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28687","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-24484","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24484","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24484"},"relatedVulnerabilities":[{"id":"CVE-2026-24484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0349df6d43d633bd61bb582d1e1e87d6332de32a","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wg3g-gvx5-2pmv","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24484","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24484","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24484","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24484"},"relatedVulnerabilities":[{"id":"CVE-2026-24484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0349df6d43d633bd61bb582d1e1e87d6332de32a","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wg3g-gvx5-2pmv","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24484","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24484","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24484","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24484"},"relatedVulnerabilities":[{"id":"CVE-2026-24484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0349df6d43d633bd61bb582d1e1e87d6332de32a","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wg3g-gvx5-2pmv","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24484","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24484","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24484","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24484"},"relatedVulnerabilities":[{"id":"CVE-2026-24484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0349df6d43d633bd61bb582d1e1e87d6332de32a","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wg3g-gvx5-2pmv","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24484","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24484","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24484","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24484"},"relatedVulnerabilities":[{"id":"CVE-2026-24484","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24484","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24484","date":"2026-10-08","epss":0.00417,"percentile":0.33922}],"urls":["https://github.com/ImageMagick/ImageMagick/commit/0349df6d43d633bd61bb582d1e1e87d6332de32a","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wg3g-gvx5-2pmv","https://github.com/dlemstra/Magick.NET/releases/tag/14.10.3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24484","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-46523","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46523","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46523"},"relatedVulnerabilities":[{"id":"CVE-2026-46523","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5r4x-w6p5-222q","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46523","https://bugzilla.redhat.com/show_bug.cgi?id=2487743","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46523.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46523","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46523","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46523","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46523"},"relatedVulnerabilities":[{"id":"CVE-2026-46523","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5r4x-w6p5-222q","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46523","https://bugzilla.redhat.com/show_bug.cgi?id=2487743","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46523.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46523","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46523","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46523","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46523"},"relatedVulnerabilities":[{"id":"CVE-2026-46523","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5r4x-w6p5-222q","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46523","https://bugzilla.redhat.com/show_bug.cgi?id=2487743","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46523.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46523","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46523","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46523","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46523"},"relatedVulnerabilities":[{"id":"CVE-2026-46523","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5r4x-w6p5-222q","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46523","https://bugzilla.redhat.com/show_bug.cgi?id=2487743","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46523.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46523","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46523","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46523","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"risk":0.20850000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46523"},"relatedVulnerabilities":[{"id":"CVE-2026-46523","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46523","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-46523","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46523","date":"2026-10-08","epss":0.00417,"percentile":0.33917}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5r4x-w6p5-222q","https://access.redhat.com/errata/RHSA-2026:32961","https://access.redhat.com/security/cve/CVE-2026-46523","https://bugzilla.redhat.com/show_bug.cgi?id=2487743","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46523.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46523","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger a heap-use-after-free. Versions 7.1.2.23 and 6.9.13-48 fix the issue."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-55160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55160"},"relatedVulnerabilities":[{"id":"CVE-2025-55160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hgw-6x87-578x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55160","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55160"},"relatedVulnerabilities":[{"id":"CVE-2025-55160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hgw-6x87-578x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55160","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55160"},"relatedVulnerabilities":[{"id":"CVE-2025-55160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hgw-6x87-578x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55160","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55160"},"relatedVulnerabilities":[{"id":"CVE-2025-55160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hgw-6x87-578x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55160","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-55160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-55160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"risk":0.207,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-55160"},"relatedVulnerabilities":[{"id":"CVE-2025-55160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-55160","cwe":"CWE-758","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-55160","date":"2026-10-08","epss":0.00414,"percentile":0.33603}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hgw-6x87-578x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-55160","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25897","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25897","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25897"},"relatedVulnerabilities":[{"id":"CVE-2026-25897","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6j5f-24fw-pqp4"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25897","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25897","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25897","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25897"},"relatedVulnerabilities":[{"id":"CVE-2026-25897","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6j5f-24fw-pqp4"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25897","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25897","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25897","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25897"},"relatedVulnerabilities":[{"id":"CVE-2026-25897","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6j5f-24fw-pqp4"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25897","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25897","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25897","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25897"},"relatedVulnerabilities":[{"id":"CVE-2026-25897","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6j5f-24fw-pqp4"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25897","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25897","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25897","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25897"},"relatedVulnerabilities":[{"id":"CVE-2026-25897","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25897","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25897","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25897","date":"2026-10-08","epss":0.00412,"percentile":0.33386}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6j5f-24fw-pqp4"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25897","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4014","versionConstraint":"<1.24.8||>=1.25.0,<1.25.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4014","fix":{"state":"fixed","versions":["1.24.8","1.25.2"],"available":[{"date":"2025-10-07","kind":"release","version":"1.24.8"},{"date":"2025-10-07","kind":"release","version":"1.25.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"risk":0.20599499999999996,"urls":["https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/709861","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."},"relatedVulnerabilities":[{"id":"CVE-2025-58183","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-58183","date":"2026-10-08","epss":0.00443,"percentile":0.36489}],"urls":["https://go.dev/cl/709861","https://go.dev/issue/75677","https://groups.google.com/g/golang-announce/c/4Emdl2iQ_bI","https://pkg.go.dev/vuln/GO-2025-4014","http://www.openwall.com/lists/oss-security/2025/10/08/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58183","description":"tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a large number of sparse regions can cause a Reader to read an unbounded amount of data from the archive into memory. When reading from a compressed source, a small compressed input can result in large allocations."}]},{"artifact":{"id":"40beb4f8a2ae0009","cpes":["cpe:2.3:a:cryptography.io:cryptography:43.0.3:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:43.0.3:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@43.0.3","type":"python","version":"43.0.3","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/METADATA","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/RECORD","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/lsiopy/lib/python3.12/site-packages/cryptography-43.0.3.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"49.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jwv3-5hgf-82ww","versionConstraint":">=42.0.0,<49.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"43.0.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-jwv3-5hgf-82ww","fix":{"state":"fixed","versions":["49.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"49.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-08","epss":0.00252,"percentile":0.15305}],"risk":0.20412,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://nvd.nist.gov/vuln/detail/CVE-2026-69249","https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jwv3-5hgf-82ww","description":"python-cryptography: Duplicate self-signed intermediates can cause exponential path-building"},"relatedVulnerabilities":[{"id":"CVE-2026-69249","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-08","epss":0.00252,"percentile":0.15305}],"urls":["https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69249","description":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0."}]},{"artifact":{"id":"7d0f7a9515ec6de4","cpes":["cpe:2.3:a:xdg-utils:xdg-utils:1.1.3-4.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:xdg-utils:xdg_utils:1.1.3-4.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:xdg_utils:xdg-utils:1.1.3-4.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:xdg_utils:xdg_utils:1.1.3-4.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg-utils:1.1.3-4.1ubuntu3:*:*:*:*:*:*:*","cpe:2.3:a:xdg:xdg_utils:1.1.3-4.1ubuntu3:*:*:*:*:*:*:*"],"name":"xdg-utils","purl":"pkg:deb/ubuntu/xdg-utils@1.1.3-4.1ubuntu3?arch=all&distro=ubuntu-24.04","type":"deb","version":"1.1.3-4.1ubuntu3","language":"","licenses":["Expat"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/xdg-utils/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/xdg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-utils.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/xdg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/xdg-utils.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/xdg-utils.list"},{"path":"/var/lib/dpkg/info/xdg-utils.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/xdg-utils.postinst"},{"path":"/var/lib/dpkg/info/xdg-utils.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/xdg-utils.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-4055","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"xdg-utils","version":"1.1.3-4.1ubuntu3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-4055","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-4055","cwe":"CWE-146","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4055","date":"2026-10-08","epss":0.00678,"percentile":0.50827}],"risk":0.20339999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-4055"},"relatedVulnerabilities":[{"id":"CVE-2022-4055","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4055","cwe":"CWE-146","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2022-4055","date":"2026-10-08","epss":0.00678,"percentile":0.50827}],"urls":["https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/205#note_1494267"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4055","description":"When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked."}]},{"artifact":{"id":"c4efc37ba8e6101d","cpes":["cpe:2.3:a:python3-setuptools-whl:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools-whl:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_whl:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_whl:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*"],"name":"python3-setuptools-whl","purl":"pkg:deb/ubuntu/python3-setuptools-whl@68.1.2-2ubuntu1.2?arch=all&distro=ubuntu-24.04&upstream=setuptools","type":"deb","version":"68.1.2-2ubuntu1.2","language":"","licenses":["Apache-2.0","BSD-3-Clause","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-setuptools-whl/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3-setuptools-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-setuptools-whl.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-setuptools-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-setuptools-whl.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3-setuptools-whl.list"}],"upstreams":[{"name":"setuptools"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59890","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"setuptools","version":"68.1.2-2ubuntu1.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-59890","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"risk":0.20249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-59890"},"relatedVulnerabilities":[{"id":"CVE-2026-59890","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"urls":["https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f","https://github.com/pypa/setuptools/releases/tag/v83.0.0","https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59890","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-93990"},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"f2f9ea64412a82e3","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/ubuntu/libavahi-client3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.19979999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52616"},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"e190b3f2d6ee823a","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/ubuntu/libavahi-common-data@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.19979999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52616"},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"1439f27e2c1f750c","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/ubuntu/libavahi-common3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.19979999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52616"},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-24481","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24481","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"risk":0.1975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24481"},"relatedVulnerabilities":[{"id":"CVE-2026-24481","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-96pc-27rx-pr36"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24481","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24481","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24481","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"risk":0.1975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24481"},"relatedVulnerabilities":[{"id":"CVE-2026-24481","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-96pc-27rx-pr36"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24481","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24481","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24481","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"risk":0.1975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24481"},"relatedVulnerabilities":[{"id":"CVE-2026-24481","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-96pc-27rx-pr36"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24481","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24481","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24481","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"risk":0.1975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24481"},"relatedVulnerabilities":[{"id":"CVE-2026-24481","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-96pc-27rx-pr36"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24481","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24481","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-24481","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"risk":0.1975,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-24481"},"relatedVulnerabilities":[{"id":"CVE-2026-24481","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24481","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24481","date":"2026-10-08","epss":0.00395,"percentile":0.31627}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-96pc-27rx-pr36"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24481","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file containing ZIP-compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:8e301c95580c04da8181974328404a22ce5c6d9cee93f4339563cfcc75977f4f","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"d303102260f7df76","cpes":["cpe:2.3:a:golang:go:1.17.8:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.17.8","type":"go-module","version":"go1.17.8","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.17.8"},"locations":[{"path":"/usr/bin/kepubify","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/bin/kepubify","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.17.8"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"446bdf2f3d1206f1","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.7-1.2ubuntu7.14:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/ubuntu/libcups2t64@2.4.7-1.2ubuntu7.14?arch=amd64&distro=ubuntu-24.04&upstream=cups","type":"deb","version":"2.4.7-1.2ubuntu7.14","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87875","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"cups","version":"2.4.7-1.2ubuntu7.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87875","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87875","date":"2026-10-08","epss":0.00392,"percentile":0.31212}],"risk":0.196,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87875"},"relatedVulnerabilities":[{"id":"CVE-2026-87875","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87875","date":"2026-10-08","epss":0.00392,"percentile":0.31212}],"urls":["https://access.redhat.com/errata/RHSA-2026:66600","https://access.redhat.com/security/cve/CVE-2026-87875","https://bugzilla.redhat.com/show_bug.cgi?id=2530994","https://github.com/OpenPrinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142","https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4","https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87875","description":"The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25982","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25982","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"risk":0.196,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25982"},"relatedVulnerabilities":[{"id":"CVE-2026-25982","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pmq6-8289-hx3v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25982","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/dcm.c` module. When processing DICOM files with a specific configuration, the decoder loop incorrectly reads bytes per iteration. This causes the function to read past the end of the allocated buffer, potentially leading to a Denial of Service (crash) or Information Disclosure (leaking heap memory into the image). Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25982","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25982","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"risk":0.196,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25982"},"relatedVulnerabilities":[{"id":"CVE-2026-25982","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pmq6-8289-hx3v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25982","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/dcm.c` module. When processing DICOM files with a specific configuration, the decoder loop incorrectly reads bytes per iteration. This causes the function to read past the end of the allocated buffer, potentially leading to a Denial of Service (crash) or Information Disclosure (leaking heap memory into the image). Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25982","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25982","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"risk":0.196,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25982"},"relatedVulnerabilities":[{"id":"CVE-2026-25982","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pmq6-8289-hx3v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25982","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/dcm.c` module. When processing DICOM files with a specific configuration, the decoder loop incorrectly reads bytes per iteration. This causes the function to read past the end of the allocated buffer, potentially leading to a Denial of Service (crash) or Information Disclosure (leaking heap memory into the image). Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"2caaf637066a5a41","cpes":["cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16-7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16_7t64:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore-6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore_6.q16:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickcore:libmagickcore_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickcore-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickcore-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickcore-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickcore-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25982","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25982","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"risk":0.196,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25982"},"relatedVulnerabilities":[{"id":"CVE-2026-25982","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pmq6-8289-hx3v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25982","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/dcm.c` module. When processing DICOM files with a specific configuration, the decoder loop incorrectly reads bytes per iteration. This causes the function to read past the end of the allocated buffer, potentially leading to a Denial of Service (crash) or Information Disclosure (leaking heap memory into the image). Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"bb7ea65e83d3f781","cpes":["cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16-7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16_7t64:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand-6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand_6.q16:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand-6.q16-7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:libmagickwand:libmagickwand_6.q16_7t64:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"libmagickwand-6.q16-7t64","purl":"pkg:deb/ubuntu/libmagickwand-6.q16-7t64@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/libmagickwand-6.q16-7t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/libmagickwand-6.q16-7t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25982","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25982","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"risk":0.196,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25982"},"relatedVulnerabilities":[{"id":"CVE-2026-25982","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25982","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25982","date":"2026-10-08","epss":0.00392,"percentile":0.31163}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-pmq6-8289-hx3v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25982","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap out-of-bounds read vulnerability exists in the `coders/dcm.c` module. When processing DICOM files with a specific configuration, the decoder loop incorrectly reads bytes per iteration. This causes the function to read past the end of the allocated buffer, potentially leading to a Denial of Service (crash) or Information Disclosure (leaking heap memory into the image). Versions 7.1.2-15 and 6.9.13-40 contain a patch."}]},{"artifact":{"id":"96b22ec6be3f92c8","cpes":["cpe:2.3:a:imagemagick:imagemagick:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick","purl":"pkg:deb/ubuntu/imagemagick@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56378","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56378","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56378","date":"2026-10-08","epss":0.00389,"percentile":0.30888}],"risk":0.19449999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56378"},"relatedVulnerabilities":[{"id":"CVE-2026-56378","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56378","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56378","date":"2026-10-08","epss":0.00389,"percentile":0.30888}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wgxp-q8xq-wpp9","https://www.vulncheck.com/advisories/imagemagick-heap-out-of-bounds-read-in-pcd-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56378","description":"ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte."}]},{"artifact":{"id":"96b551fd9d61793d","cpes":["cpe:2.3:a:imagemagick-6-common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6-common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6_common:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6-common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6_common:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6-common","purl":"pkg:deb/ubuntu/imagemagick-6-common@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=all&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6-common/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6-common.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6-common.list"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56378","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56378","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56378","date":"2026-10-08","epss":0.00389,"percentile":0.30888}],"risk":0.19449999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56378"},"relatedVulnerabilities":[{"id":"CVE-2026-56378","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56378","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56378","date":"2026-10-08","epss":0.00389,"percentile":0.30888}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wgxp-q8xq-wpp9","https://www.vulncheck.com/advisories/imagemagick-heap-out-of-bounds-read-in-pcd-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56378","description":"ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte."}]},{"artifact":{"id":"7ee7cd836e418208","cpes":["cpe:2.3:a:imagemagick-6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick-6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick_6.q16:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick-6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*","cpe:2.3:a:imagemagick:imagemagick_6.q16:8\\:6.9.12.98\\+dfsg1-5.2build2:*:*:*:*:*:*:*"],"name":"imagemagick-6.q16","purl":"pkg:deb/ubuntu/imagemagick-6.q16@8%3A6.9.12.98%2Bdfsg1-5.2build2?arch=amd64&distro=ubuntu-24.04&upstream=imagemagick","type":"deb","version":"8:6.9.12.98+dfsg1-5.2build2","language":"","licenses":["Artistic","BSD-with-FSF-change-public-domain","GNU-All-Permissive-License","GPL-1","GPL-2","GPL-2+","GPL-3","GPL2+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception","GPL3+-with-Autoconf-Macros-exception-GNU","ImageMagick","ImageMagickLicensePartEZXML","ImageMagickLicensePartFIG","ImageMagickLicensePartGsview","ImageMagickLicensePartOpenSSH","ImageMagickPartGraphicsMagick","ImageMagickPartlibjpeg","ImageMagickPartlibsquish","LGPL-3","LGPL-3+","Magick++","Makefile-in","Perllikelicence","aclocal"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/imagemagick-6.q16/copyright","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/usr/share/doc/imagemagick-6.q16/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.list","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.list"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.postinst","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.postinst"},{"path":"/var/lib/dpkg/info/imagemagick-6.q16.prerm","layerID":"sha256:a3423426ef3f4eb58a7a12d63e1ffd6beb33bf6053e538ad395b4d36f7611343","accessPath":"/var/lib/dpkg/info/imagemagick-6.q16.prerm"}],"upstreams":[{"name":"imagemagick"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56378","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2build2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56378","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56378","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56378","date":"2026-10-08","epss":0.00389,"percentile":0.30888}],"risk":0.19449999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56378"},"relatedVulnerabilities":[{"id":"CVE-2026-56378","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56378","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56378","date":"2026-10-08","epss":0.00389,"percentile":0.30888}],"urls":["https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-wgxp-q8xq-wpp9","https://www.vulncheck.com/advisories/imagemagick-heap-out-of-bounds-read-in-pcd-decoder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56378","description":"ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T22:49:20.957Z","grype_db_version":"2026-10-09T06:32:32.000Z"}