{"grype_matches":[{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-07","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-07","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-07","epss":0.04002,"percentile":0.90268}],"risk":3.12156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification.  Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution.  When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition.  In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution.  Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-07","epss":0.04002,"percentile":0.90268}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"62f27adbe6fb6265","cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"name":"krb5","purl":"pkg:generic/krb5@1.21.3","type":"binary","version":"1.21.3","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2007-5894","versionConstraint":"none (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"package":{"name":"krb5","version":"1.21.3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2007-5894","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","metrics":{"baseScore":9.3,"impactScore":10.1,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2007-5894","date":"2026-10-07","epss":0.02685,"percentile":0.85396}],"risk":2.2554000000000003,"urls":["http://bugs.gentoo.org/show_bug.cgi?id=199205","http://osvdb.org/44333","http://seclists.org/fulldisclosure/2007/Dec/0176.html","http://seclists.org/fulldisclosure/2007/Dec/0321.html","http://secunia.com/advisories/28636","http://secunia.com/advisories/29457","http://wiki.rpath.com/Advisories:rPSA-2008-0112","http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0112","http://www.novell.com/linux/security/advisories/suse_security_summary_report.html","http://www.securityfocus.com/archive/1/489883/100/0/threaded","http://www.securityfocus.com/bid/26750","https://issues.rpath.com/browse/RPL-2012"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-5894","description":"The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors.  NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used.  NOTE: the vendor disputes this issue, stating \" The 'length' variable is only uninitialized if 'auth_type' is neither the 'KERBEROS_V4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code."},"relatedVulnerabilities":[]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"< 3.5.5-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"fixed","versions":["3.5.5-1~deb13u2"],"available":[{"date":"2026-04-07","kind":"advisory","version":"3.5.5-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-07","epss":0.02501,"percentile":0.84222}],"risk":1.87575,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6201-1","link":"https://security-tracker.debian.org/tracker/DSA-6201-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the delta CRL processing does not check whether the CRL Number extension is NULL before dereferencing it. When a malformed delta CRL file is being processed, this parameter can be NULL, causing a NULL pointer dereference.  Exploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in the verification context, the certificate being verified to contain a freshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and an attacker to provide a malformed CRL to an application that processes it.  The vulnerability is limited to Denial of Service and cannot be escalated to achieve code execution or memory disclosure. For that reason the issue was assessed as Low severity according to our Security Policy.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-07","epss":0.02501,"percentile":0.84222}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"< 3.5.5-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"fixed","versions":["3.5.5-1~deb13u2"],"available":[{"date":"2026-04-07","kind":"advisory","version":"3.5.5-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-07","epss":0.02435,"percentile":0.83774}],"risk":1.8262500000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6201-1","link":"https://security-tracker.debian.org/tracker/DSA-6201-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-07","epss":0.02435,"percentile":0.83774}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-07","epss":0.01602,"percentile":0.75061}],"risk":1.2015,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.  Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.  CWE: CWE-476: NULL Pointer Dereference  Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.  This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-07","epss":0.01602,"percentile":0.75061}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18798","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18798","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-07","epss":0.01537,"percentile":0.74091}],"risk":1.15275,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet.  Impact summary: Double free leads to heap corruption, which typically results in  termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable.  CWE: CWE-415: Double Free  Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time.  The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length.  FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-18798","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18798","cwe":"CWE-415","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-18798","date":"2026-10-07","epss":0.01537,"percentile":0.74091}],"urls":["https://github.com/openssl/openssl/commit/70cebd74d3592f5272945501b58a60374c4e13af","https://github.com/openssl/openssl/commit/967582d5037f01a26b6d19beae19af62a1b15c3c","https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18798","description":"Issue summary: QUIC server may double free QRX (QUIC record layer RX) object\nwhen channel creation fails for initial packet.\n\nImpact summary: Double free leads to heap corruption, which typically results in \ntermination of QUIC server process, leading to Denial of Service. There is so\nfar no evidence that this double free is exploitable for remote code execution,\nthus it is considered highly improbable.\n\nCWE: CWE-415: Double Free\n\nDescription: In order to validate initial packet, OpenSSL QUIC stack default\npacket handler (port_default_packet_handler()) creates a so-called QRX object.\nIf the initial packet validates successfully with QRX object, the default packet\nhandler proceeds to channel (connection object) creation. The QRX object used\nfor packet validation is passed to port_bind_channel(), so it becomes part of\nthe newly created connection. If port_bind_channel() fails, then it also frees\nthe QRX object. Once port_bind_channel() returns, the port_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX object is\nfreed for the second time.\n\nThe failure in port_bind_channel() function can be induced with a relatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet\ncarries DCID (destination connection ID) which is shorter than 8 bytes, then\nport_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\n\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63073","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63073","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-07","epss":0.01159,"percentile":0.66113}],"risk":1.08946,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`.  Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.  CWE: CWE-134 (Use of Externally-Controlled Format String)  Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses.  Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution.  FIPS impact: no  No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63073","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63073","cwe":"CWE-134","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63073","date":"2026-10-07","epss":0.01159,"percentile":0.66113}],"urls":["https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca","https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29","https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21","https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63073","description":"Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34180","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34180","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-07","epss":0.01311,"percentile":0.69774}],"risk":0.9832500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms.  Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer.  More typically such ASN.1 elements would instead be truncated.  An integer truncation in OpenSSL's ASN.1 decoder causes the content length of an ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the worst case the truncated length is treated as a request to scan the binary content for a terminating zero byte, possibly causing OpenSSL to read either less than or beyond the end of the allocated buffer.  Applications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or any other d2i_* decoding function are affected. OpenSSL's own command-line tools are not vulnerable, as data read through the BIO layer is checked before it reaches the affected code. The issue only affects 64-bit Unix and Unix-like platforms; 32-bit platforms and 64-bit Windows are not affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-34180","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-07","epss":0.01311,"percentile":0.69774}],"urls":["https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d","https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83","https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff","https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43","https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34182","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34182","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-07","epss":0.01057,"percentile":0.63382}],"risk":0.9565849999999999,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34182","description":"Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises.  Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given message.  In one use case, an attacker may send a CMS message containing AuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL erroneously allows this selection, and attempts to decrypt and validate the message.  An on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData addressed to the victim can re-emit it with the recipientInfos set left byte-for-byte intact, so the victim's private key still unwraps the genuine CEK (the content-encryption key), but with the inner OID rewritten to AES-256-OFB (Output Feedback Mode, an unauthenticated keystream mode) and with an attacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the real CEK, never consults the MAC field, and CMS_decrypt() returns success.  If the application under attack responds to the attacker with any indicator showing success or failure of the decryption effort, it is possible for the attacker to use this as an oracle to obtain key equivalent functionality for the CEK used for the chosen recipient of the message.  In another use case, an attacker can reduce the tag length of the chosen AEAD cipher for a given AuthEnvelopedData container to be a single byte long, allowing an attacker to brute force CMS decryption, producing an integrity bypass for applications that trust CMS_decrypt() to reject modified content.  The FIPS modules are not affected by this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-34182","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-07","epss":0.01057,"percentile":0.63382}],"urls":["https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc","https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f","https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7","https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac","https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34182","description":"Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42010","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42010","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42010","date":"2026-10-07","epss":0.00944,"percentile":0.59841}],"risk":0.88736,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42010","description":"A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process."},"relatedVulnerabilities":[{"id":"CVE-2026-42010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42010","date":"2026-10-07","epss":0.00944,"percentile":0.59841}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:34790","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42010","https://bugzilla.redhat.com/show_bug.cgi?id=2467289","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42010","description":"A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process."}]},{"artifact":{"id":"04ef2a4cf087de67","cpes":["cpe:2.3:a:libtasn1-6:libtasn1-6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1-6:libtasn1_6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1-6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1_6:libtasn1_6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1-6:4.20.0-2:*:*:*:*:*:*:*","cpe:2.3:a:libtasn1:libtasn1_6:4.20.0-2:*:*:*:*:*:*:*"],"name":"libtasn1-6","purl":"pkg:deb/debian/libtasn1-6@4.20.0-2?arch=amd64&distro=debian-13.3","type":"deb","version":"4.20.0-2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libtasn1-6","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libtasn1-6","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.20.0-2+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-13151","versionConstraint":"< 4.20.0-2+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libtasn1-6","version":"4.20.0-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-13151","fix":{"state":"fixed","versions":["4.20.0-2+deb13u1"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"4.20.0-2+deb13u1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-07","epss":0.01175,"percentile":0.66595}],"risk":0.8812500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."},"relatedVulnerabilities":[{"id":"CVE-2025-13151","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-07","epss":0.01175,"percentile":0.66595}],"urls":["https://gitlab.com/gnutls/libtasn1","https://gitlab.com/gnutls/libtasn1/-/merge_requests/121","http://www.openwall.com/lists/oss-security/2026/01/08/5","https://www.kb.cert.org/vuls/id/271649"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42009","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42009","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42009","date":"2026-10-07","epss":0.01129,"percentile":0.65345}],"risk":0.8467499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42009","description":"A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-42009","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42009","date":"2026-10-07","epss":0.01129,"percentile":0.65345}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:29794","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42009","https://bugzilla.redhat.com/show_bug.cgi?id=2467279","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42009","description":"A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33846","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-33846","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33846","date":"2026-10-07","epss":0.01123,"percentile":0.65194}],"risk":0.8422499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-33846","description":"A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-33846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33846","date":"2026-10-07","epss":0.01123,"percentile":0.65194}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33846","https://bugzilla.redhat.com/show_bug.cgi?id=2450625","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33846","description":"A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6473","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6473","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6473","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6473","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6473","date":"2026-10-07","epss":0.01006,"percentile":0.61869}],"risk":0.81989,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"},{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6473","description":"Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6473","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6473","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6473","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6473","date":"2026-10-07","epss":0.01006,"percentile":0.61869}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6473/","https://access.redhat.com/errata/RHSA-2026:22878","https://access.redhat.com/errata/RHSA-2026:26181","https://access.redhat.com/errata/RHSA-2026:26203","https://access.redhat.com/errata/RHSA-2026:26204","https://access.redhat.com/errata/RHSA-2026:26524","https://access.redhat.com/errata/RHSA-2026:26525","https://access.redhat.com/errata/RHSA-2026:26561","https://access.redhat.com/errata/RHSA-2026:27718","https://access.redhat.com/errata/RHSA-2026:27738","https://access.redhat.com/errata/RHSA-2026:27741","https://access.redhat.com/errata/RHSA-2026:27742","https://access.redhat.com/errata/RHSA-2026:27743","https://access.redhat.com/errata/RHSA-2026:28037","https://access.redhat.com/errata/RHSA-2026:28143","https://access.redhat.com/errata/RHSA-2026:28208","https://access.redhat.com/errata/RHSA-2026:28999","https://access.redhat.com/errata/RHSA-2026:29212","https://access.redhat.com/errata/RHSA-2026:29815","https://access.redhat.com/errata/RHSA-2026:29904","https://access.redhat.com/errata/RHSA-2026:29953","https://access.redhat.com/errata/RHSA-2026:32983","https://access.redhat.com/errata/RHSA-2026:32994","https://access.redhat.com/errata/RHSA-2026:33441","https://access.redhat.com/errata/RHSA-2026:33497","https://access.redhat.com/errata/RHSA-2026:34043","https://access.redhat.com/errata/RHSA-2026:34362","https://access.redhat.com/errata/RHSA-2026:34363","https://access.redhat.com/errata/RHSA-2026:35880","https://access.redhat.com/errata/RHSA-2026:42555","https://access.redhat.com/errata/RHSA-2026:44420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:44568","https://access.redhat.com/errata/RHSA-2026:49521","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-6473","https://bugzilla.redhat.com/show_bug.cgi?id=2477448","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6473.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6473","description":"Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33845","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-33845","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-07","epss":0.00886,"percentile":0.58004}],"risk":0.80183,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-33845","description":"A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-33845","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-07","epss":0.00886,"percentile":0.58004}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33845","https://bugzilla.redhat.com/show_bug.cgi?id=2450624","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33845","description":"A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34183","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34183","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34183","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34183","date":"2026-10-07","epss":0.01049,"percentile":0.63177}],"risk":0.78675,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34183","description":"Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.  Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.  A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-34183","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34183","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34183","date":"2026-10-07","epss":0.01049,"percentile":0.63177}],"urls":["https://github.com/openssl/openssl/commit/5b306efb0b3779dfdd0803b4afc9d08c91f11517","https://github.com/openssl/openssl/commit/7d06955ebe0ecf8adfd4c1e92018586da47ef9ac","https://github.com/openssl/openssl/commit/d2e9efbe4900a373227deb136e8665401404ffac","https://github.com/openssl/openssl/commit/fbaa83859c01ad64f497b757aaf51be7d05ed9eb","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34183","description":"Issue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\n\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\n\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-31790","versionConstraint":"< 3.5.5-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-31790","fix":{"state":"fixed","versions":["3.5.5-1~deb13u2"],"available":[{"date":"2026-04-07","kind":"advisory","version":"3.5.5-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31790","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31790","date":"2026-10-07","epss":0.0103,"percentile":0.62614}],"risk":0.7725,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6201-1","link":"https://security-tracker.debian.org/tracker/DSA-6201-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31790","description":"Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer.  Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker.  RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced.  If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker in place of the KEM ciphertext.  As a workaround calling EVP_PKEY_public_check() or EVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate the issue.  The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-31790","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31790","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31790","date":"2026-10-07","epss":0.0103,"percentile":0.62614}],"urls":["https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac","https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482","https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406","https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790","https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31790","description":"Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14457","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14457","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-07","epss":0.01021,"percentile":0.62304}],"risk":0.76575,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted \"signature_algorithms_cert\" TLS extension.  Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible.  CWE: CWE-476: NULL Pointer Dereference  Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA).  When the private key is configured along with a matching certificate, the \"signature_algorithms_cert\" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key.  Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below.  FIPS impact: no  No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14457","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14457","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14457","date":"2026-10-07","epss":0.01021,"percentile":0.62304}],"urls":["https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76","https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1","https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f","https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14457","description":"Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7598","versionConstraint":"< 1.11.1-1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7598","fix":{"state":"fixed","versions":["1.11.1-1+deb13u1"],"available":[{"date":"2026-06-25","kind":"advisory","version":"1.11.1-1+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7598","cwe":"CWE-189","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-7598","cwe":"CWE-190","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-7598","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-7598","date":"2026-10-07","epss":0.00824,"percentile":0.56036}],"risk":0.74572,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6365-1","link":"https://security-tracker.debian.org/tracker/DSA-6365-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7598","description":"A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-7598","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7598","cwe":"CWE-189","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-7598","cwe":"CWE-190","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-7598","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-7598","date":"2026-10-07","epss":0.00824,"percentile":0.56036}],"urls":["https://github.com/libssh2/libssh2/","https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1","https://github.com/libssh2/libssh2/pull/1858","https://vuldb.com/submit/805564","https://vuldb.com/vuln/360555","https://vuldb.com/vuln/360555/cti","https://access.redhat.com/errata/RHSA-2026:16736","https://access.redhat.com/errata/RHSA-2026:61752","https://access.redhat.com/errata/RHSA-2026:7021","https://access.redhat.com/security/cve/CVE-2026-7598","https://bugzilla.redhat.com/show_bug.cgi?id=2464597","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7598.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7598","description":"A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5260","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5260","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5260","date":"2026-10-07","epss":0.00945,"percentile":0.59865}],"risk":0.741825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5260","description":"A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5260","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5260","date":"2026-10-07","epss":0.00945,"percentile":0.59865}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:67837","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5260","https://bugzilla.redhat.com/show_bug.cgi?id=2467450","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5260","description":"A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"< 3.5.5-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"fixed","versions":["3.5.5-1~deb13u2"],"available":[{"date":"2026-04-07","kind":"advisory","version":"3.5.5-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-07","epss":0.00943,"percentile":0.59817}],"risk":0.73554,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6201-1","link":"https://security-tracker.debian.org/tracker/DSA-6201-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage.  By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages.  These SMTP (or other similar) clients are not vulnerable to this issue.  Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable.  The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records.  No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-07","epss":0.00943,"percentile":0.59817}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9076","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9076","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-07","epss":0.00973,"percentile":0.60807}],"risk":0.72975,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher can trigger a heap out-of-bounds read in kek_unwrap_key().  Impact summary: A heap buffer over-read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmapped. There is no information disclosure as the over-read bytes are not revealed to the attacker.  The key unwrapping function performs a check-byte test as specified in the RFC that reads 7 bytes from a heap allocation that is based on the wrapped key length from the message. There is a minimum length check based on the block length of the wrapping cipher. However the cipher is selected from an OID carried in the attacker's PWRI keyEncryptionAlgorithm with no requirement that the cipher be a block cipher. When an attacker selects a stream-mode cipher the guard will be ineffective and the allocated buffer containing the unwrapped key can be too small to fit the check-bytes specified in the RFC and a buffer over-read can happen.  Applications calling CMS_decrypt() or CMS_decrypt_set1_password() (equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS data are vulnerable to this issue. No password knowledge is required: the over-read happens during the unwrap attempt before any authentication succeeds.  The over-read is limited to a few bytes and is not written to output, so there is no information disclosure. Triggering a crash requires the allocation to border unmapped memory, which is unlikely with the normal allocator.  The FIPS modules are not affected by this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-9076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-07","epss":0.00973,"percentile":0.60807}],"urls":["https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb","https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0","https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98","https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26","https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3805","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3805","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3805","date":"2026-10-07","epss":0.00951,"percentile":0.60073}],"risk":0.7132499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3805","description":"When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory."},"relatedVulnerabilities":[{"id":"CVE-2026-3805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3805","date":"2026-10-07","epss":0.00951,"percentile":0.60073}],"urls":["https://curl.se/docs/CVE-2026-3805.html","https://curl.se/docs/CVE-2026-3805.json","https://hackerone.com/reports/3591944","http://www.openwall.com/lists/oss-security/2026/03/11/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3805","description":"When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-07","epss":0.00916,"percentile":0.58962}],"risk":0.6869999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.  Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.  The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.  FIPS impact: no  As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-07","epss":0.00916,"percentile":0.58962}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 2.41-12+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["2.41-12+deb13u4"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"2.41-12+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-07","epss":0.00718,"percentile":0.52406}],"risk":0.6749200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-07","epss":0.00718,"percentile":0.52406}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"fa925028c58e5356","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.64.0-1.1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/debian/libnghttp2-14@1.64.0-1.1?arch=amd64&distro=debian-13.3&upstream=nghttp2","type":"deb","version":"1.64.0-1.1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libnghttp2-14","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libnghttp2-14","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.64.0-1.1+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27135","versionConstraint":"< 1.64.0-1.1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"nghttp2","version":"1.64.0-1.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27135","fix":{"state":"fixed","versions":["1.64.0-1.1+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"1.64.0-1.1+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27135","date":"2026-10-07","epss":0.00892,"percentile":0.58169}],"risk":0.669,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6266-1","link":"https://security-tracker.debian.org/tracker/DSA-6266-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27135","description":"nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available."},"relatedVulnerabilities":[{"id":"CVE-2026-27135","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27135","date":"2026-10-07","epss":0.00892,"percentile":0.58169}],"urls":["https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1","https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6","http://www.openwall.com/lists/oss-security/2026/03/20/3","https://lists.debian.org/debian-lts-announce/2026/05/msg00025.html","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14773","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:15087","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:17596","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:20040","https://access.redhat.com/errata/RHSA-2026:20087","https://access.redhat.com/errata/RHSA-2026:21656","https://access.redhat.com/errata/RHSA-2026:21690","https://access.redhat.com/errata/RHSA-2026:21695","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:27200","https://access.redhat.com/errata/RHSA-2026:27201","https://access.redhat.com/errata/RHSA-2026:6190","https://access.redhat.com/errata/RHSA-2026:7080","https://access.redhat.com/errata/RHSA-2026:7123","https://access.redhat.com/errata/RHSA-2026:7302","https://access.redhat.com/errata/RHSA-2026:7310","https://access.redhat.com/errata/RHSA-2026:7350","https://access.redhat.com/errata/RHSA-2026:7666","https://access.redhat.com/errata/RHSA-2026:7667","https://access.redhat.com/errata/RHSA-2026:7668","https://access.redhat.com/errata/RHSA-2026:7670","https://access.redhat.com/errata/RHSA-2026:7675","https://access.redhat.com/errata/RHSA-2026:7896","https://access.redhat.com/errata/RHSA-2026:7983","https://access.redhat.com/errata/RHSA-2026:8339","https://access.redhat.com/errata/RHSA-2026:8538","https://access.redhat.com/errata/RHSA-2026:8539","https://access.redhat.com/errata/RHSA-2026:8540","https://access.redhat.com/errata/RHSA-2026:8541","https://access.redhat.com/errata/RHSA-2026:8545","https://access.redhat.com/errata/RHSA-2026:8546","https://access.redhat.com/errata/RHSA-2026:8547","https://access.redhat.com/errata/RHSA-2026:8548","https://access.redhat.com/errata/RHSA-2026:8868","https://access.redhat.com/errata/RHSA-2026:9711","https://access.redhat.com/errata/RHSA-2026:9832","https://access.redhat.com/errata/RHSA-2026:9874","https://access.redhat.com/security/cve/CVE-2026-27135","https://bugzilla.redhat.com/show_bug.cgi?id=2448754","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27135","description":"nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3833","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3833","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3833","date":"2026-10-07","epss":0.00892,"percentile":0.58186}],"risk":0.6645400000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3833","description":"A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-3833","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3833","date":"2026-10-07","epss":0.00892,"percentile":0.58186}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-3833","https://bugzilla.redhat.com/show_bug.cgi?id=2445763","https://gitlab.com/gnutls/gnutls/-/issues/1803"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3833","description":"A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure."}]},{"artifact":{"id":"c6ebcfb78a881f6f","cpes":["cpe:2.3:a:treasuredata:fluent_bit:4.2.3:*:*:*:*:*:*:*"],"name":"fluent-bit","purl":"pkg:github/fluent/fluent-bit@4.2.3","type":"binary","version":"4.2.3","language":"","licenses":[],"locations":[{"path":"/fluent-bit/bin/fluent-bit","layerID":"sha256:1790522d16b9f23f6c6637d798b65cc88edb6c390a08085371e2ec5a10b1a71b","accessPath":"/fluent-bit/bin/fluent-bit","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.8"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-61674","versionConstraint":">= 0.11.0, < 5.0.8 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:treasuredata:fluent_bit:4.2.3:*:*:*:*:*:*:*"],"package":{"name":"fluent-bit","version":"4.2.3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-61674","fix":{"state":"fixed","versions":["5.0.8"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"5.0.8"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-61674","cwe":"CWE-121","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-61674","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-61674","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-61674","date":"2026-10-07","epss":0.0072,"percentile":0.52447}],"risk":0.6552,"urls":["https://github.com/fluent/fluent-bit/commit/45486556be9d023e194665e243f156b228e195e0","https://github.com/fluent/fluent-bit/pull/11945","https://github.com/fluent/fluent-bit/releases/tag/v5.0.8","https://github.com/fluent/fluent-bit/security/advisories/GHSA-jrp8-r9hx-gf73"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-61674","description":"Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the 32-byte stack buffer msg with memcpy without checking its MessagePack type or length. An attacker who controls or can impersonate an out_forward Secure Forward destination configured with Shared_Key or Empty_Shared_Key can send an oversized reason during the first handshake and overwrite stack control data. Protected builds reliably terminate, while builds without a stack canary or with a disclosure can allow remote code execution as the Fluent Bit process user. When the opt-in --supervisor mode is used, fork-only respawns preserve the canary and address layout, allowing repeated crash-or-survive probes to support code execution on a hardened build; ordinary exec-based or service-manager restarts do not preserve that state. This issue is fixed in version 5.0.8."},"relatedVulnerabilities":[]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-55200","versionConstraint":"< 1.11.1-1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-55200","fix":{"state":"fixed","versions":["1.11.1-1+deb13u1"],"available":[{"date":"2026-06-25","kind":"advisory","version":"1.11.1-1+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55200","cwe":"CWE-680","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-55200","date":"2026-10-07","epss":0.00825,"percentile":0.5607}],"risk":0.65175,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6365-1","link":"https://security-tracker.debian.org/tracker/DSA-6365-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-55200","description":"libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-55200","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":8.3,"impactScore":5.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55200","cwe":"CWE-680","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-55200","date":"2026-10-07","epss":0.00825,"percentile":0.5607}],"urls":["https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8","https://github.com/libssh2/libssh2/pull/2052","https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c","https://web.archive.org/web/20260623211210/https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-poc"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55200","description":"libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42766","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42766","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-07","epss":0.0111,"percentile":0.64877}],"risk":0.6049500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption.  Impact summary: This NULL pointer dereference leads to an application crash and a Denial of Service.  The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as OPTIONAL in the ASN.1 specification and may therefore be absent in specially crafted inputs. During the password-based CMS decryption the OpenSSL CMS implementation dereferences this field without first checking whether it was present.  An attacker who supplies such a CMS message to an application performing password-based CMS decryption can trigger an application crash, leading to a Denial of Service.  Applications that process password-encrypted CMS messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42766","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-07","epss":0.0111,"percentile":0.64877}],"urls":["https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce","https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4","https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7","https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4","https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28390","versionConstraint":"< 3.5.5-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-28390","fix":{"state":"fixed","versions":["3.5.5-1~deb13u2"],"available":[{"date":"2026-04-07","kind":"advisory","version":"3.5.5-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-07","epss":0.00805,"percentile":0.55397}],"risk":0.6037499999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6201-1","link":"https://security-tracker.debian.org/tracker/DSA-6201-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing.  Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-28390","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-07","epss":0.00805,"percentile":0.55397}],"urls":["https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc","https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6","https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4","https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788","https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"b6ee860d702b8084","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgssapi-krb5-2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgssapi-krb5-2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40355","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"risk":0.594,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."}]},{"artifact":{"id":"52ef833c1503e21a","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libk5crypto3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libk5crypto3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40355","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"risk":0.594,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."}]},{"artifact":{"id":"d4c94f2fc66f3184","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5-3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5-3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40355","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"risk":0.594,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."}]},{"artifact":{"id":"56fc39be304d53f0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5support0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5support0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40355","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"risk":0.594,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."}]},{"artifact":{"id":"b6ee860d702b8084","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgssapi-krb5-2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgssapi-krb5-2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40356","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"risk":0.58725,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40356","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."}]},{"artifact":{"id":"52ef833c1503e21a","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libk5crypto3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libk5crypto3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40356","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"risk":0.58725,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40356","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."}]},{"artifact":{"id":"d4c94f2fc66f3184","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5-3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5-3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40356","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"risk":0.58725,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40356","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."}]},{"artifact":{"id":"56fc39be304d53f0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5support0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5support0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.21.3-5+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40356","versionConstraint":"< 1.21.3-5+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"fixed","versions":["1.21.3-5+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.21.3-5+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"risk":0.58725,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6293-1","link":"https://security-tracker.debian.org/tracker/DSA-6293-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."},"relatedVulnerabilities":[{"id":"CVE-2026-40356","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42764","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42764","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42764","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42764","date":"2026-10-07","epss":0.00778,"percentile":0.54455}],"risk":0.5835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42764","description":"Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.  Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.  If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.  By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42764","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42764","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42764","date":"2026-10-07","epss":0.00778,"percentile":0.54455}],"urls":["https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729","https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677","https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42764","description":"Issue summary: Receiving a QUIC initial packet with an invalid token may\ntrigger a NULL pointer dereference in the OpenSSL QUIC server with\naddress validation disabled.\n\nImpact summary: NULL pointer dereference typically causes abnormal termination\nof the affected QUIC server process and a Denial of Service.\n\nIf the address validation is disabled in the OpenSSL QUIC server\nimplementation, an attacker can crash the server by sending an initial\npacket with an invalid or expired token.\n\nBy default, the client address validation is enabled in the OpenSSL QUIC server\nimplementation, which makes the default configuration not vulnerable\nto this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with\nthe SSL_new_listener() call, the address validation is disabled making the\nvulnerable code reachable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63075","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63075","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-07","epss":0.00778,"percentile":0.54455}],"risk":0.5835,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection.  Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exhaustion, especially with sustained traffic or many concurrent QUIC connections.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: When the OpenSSL QUIC stack sends an ACK-only packet, there is no requirement by the QUIC protocol that the peer will acknowledge that ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL implementation stores the metadata about the ACK frames regardless. In and of itself that's ok, but if a malicious peer establishes a connection, and then drives the connection such that ACK-only packets are forced from the  OpenSSL implementation peer (i.e., by sending numerous PING frames), and then withholding any subsequent acks for ack-eliciting data, like legitimate data, said malicious peer can force inappropriate memory growth on the OpenSSL peer, potentially leading to a Denial of Service.  The fix is to ensure that we account for the transmission of the ACK-only packet in the packet histories high and low watermark without actually storing the ACK-only packet metadata itself.  FIPS impact: no The OpenSSL FIPS module is not affected as the QUIC code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-63075","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63075","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63075","date":"2026-10-07","epss":0.00778,"percentile":0.54455}],"urls":["https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075","description":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66033","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66033","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66033","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66033","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66033","date":"2026-10-07","epss":0.00695,"percentile":0.51473}],"risk":0.56295,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66033","description":"libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs."},"relatedVulnerabilities":[{"id":"CVE-2026-66033","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66033","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66033","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66033","date":"2026-10-07","epss":0.00695,"percentile":0.51473}],"urls":["https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6","https://github.com/libssh2/libssh2/pull/2401","https://www.vulncheck.com/advisories/libssh2-integer-underflow-dos-via-aes-gcm-cipher-negotiation"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66033","description":"libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs."}]},{"artifact":{"id":"62f27adbe6fb6265","cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"name":"krb5","purl":"pkg:generic/krb5@1.21.3","type":"binary","version":"1.21.3","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40355","versionConstraint":">= 1.18.0, <= 1.22.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"package":{"name":"krb5","version":"1.21.3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-07","epss":0.00792,"percentile":0.54957}],"risk":0.56232,"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."},"relatedVulnerabilities":[]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16239","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-16239","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16239","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-16239","date":"2026-10-07","epss":0.00683,"percentile":0.51031}],"risk":0.5566450000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16239","description":"Type confusion in PostgreSQL \"portal\"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-16239","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16239","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-16239","date":"2026-10-07","epss":0.00683,"percentile":0.51031}],"urls":["https://www.postgresql.org/support/security/CVE-2026-16239/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16239","description":"Type confusion in PostgreSQL \"portal\"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"62f27adbe6fb6265","cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"name":"krb5","purl":"pkg:generic/krb5@1.21.3","type":"binary","version":"1.21.3","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-40356","versionConstraint":">= 1.18.0, <= 1.22.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"package":{"name":"krb5","version":"1.21.3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-07","epss":0.00783,"percentile":0.54634}],"risk":0.5559299999999999,"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."},"relatedVulnerabilities":[]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7383","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7383","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-07","epss":0.00701,"percentile":0.51717}],"risk":0.54678,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow.  Impact summary: A heap buffer overflow may lead to a crash or possibly attacker controlled code execution or other undefined behaviour.  In ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination size for Unicode output is computed in a signed int: by left shift of the input character count for BMPSTRING (UTF-16) and UNIVERSALSTRING (UTF-32), and by summing per-character byte counts for UTF8STRING. The calculation overflows when the input reaches around 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30 characters) the size wraps to zero, OPENSSL_malloc(1) is called, and the subsequent character copy writes several gigabytes past the one-byte allocation.  X.509 certificate processing routes through ASN1_STRING_set_by_NID(), whose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID size limits cap the input length; no network protocol or certificate-handling path in OpenSSL exercises the overflow. Triggering the bug requires an application that calls ASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers a custom string type via ASN1_STRING_TABLE_add(), with attacker-controlled input on the order of half a gigabyte or more. For these reasons this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-7383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-07","epss":0.00701,"percentile":0.51717}],"urls":["https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6","https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74","https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974","https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083","https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14456","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14456","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-07","epss":0.00729,"percentile":0.52785}],"risk":0.5467500000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.  Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection. It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests.  The issue is present since OpenSSL 3.5 when the QUIC server implementation was added.  The fix introduces a limit for pending connections. The default limit is set to 256 pending connections (waiting to be accepted by the local application). Applications may change the default by calling SSL_set_value_uint(3ossl).  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-14456","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14456","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-14456","date":"2026-10-07","epss":0.00729,"percentile":0.52785}],"urls":["https://github.com/openssl/openssl/commit/08e7756c3900bcfd77a720e7b74e27d6e4ed01a9","https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b","https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139","https://openssl-library.org/news/secadv/20260813.txt","http://www.openwall.com/lists/oss-security/2026/08/13/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456","description":"Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-07","epss":0.00692,"percentile":0.5135}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-07","epss":0.00692,"percentile":0.5135}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14669","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14669","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14669","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14669","date":"2026-10-07","epss":0.00662,"percentile":0.50107}],"risk":0.5395300000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14669","description":"Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14669","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14669","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14669","date":"2026-10-07","epss":0.00662,"percentile":0.50107}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14669/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14669","description":"Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45445","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-45445","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-07","epss":0.00704,"percentile":0.51837}],"risk":0.528,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45445","description":"Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded.  Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality.  If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message.  OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex().  The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not.  Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV.  If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext.  The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair.  The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable.  The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-45445","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-07","epss":0.00704,"percentile":0.51837}],"urls":["https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451","https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7","https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af","https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c","https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45445","description":"Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-55199","versionConstraint":"< 1.11.1-1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-55199","fix":{"state":"fixed","versions":["1.11.1-1+deb13u1"],"available":[{"date":"2026-06-25","kind":"advisory","version":"1.11.1-1+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55199","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-55199","date":"2026-10-07","epss":0.00692,"percentile":0.51363}],"risk":0.519,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6365-1","link":"https://security-tracker.debian.org/tracker/DSA-6365-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-55199","description":"libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops."},"relatedVulnerabilities":[{"id":"CVE-2026-55199","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55199","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-55199","date":"2026-10-07","epss":0.00692,"percentile":0.51363}],"urls":["https://github.com/libssh2/libssh2/commit/17626857d20b3c9a1addfa45979dadcee1cd84a4","https://github.com/libssh2/libssh2/pull/1864","https://www.vulncheck.com/advisories/libssh2-pre-authentication-dos-via-ssh-msg-ext-info-handler"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55199","description":"libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"< 2.41-12+deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"fixed","versions":["2.41-12+deb13u3"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"2.41-12+deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-07","epss":0.00662,"percentile":0.5011}],"risk":0.4965,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.    This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-07","epss":0.00662,"percentile":0.5011}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5773","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5773","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-07","epss":0.00657,"percentile":0.49868}],"risk":0.49275,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different \"share\" than the new subsequent transfer should.  This could in unlucky situations lead to the download of the wrong file or the upload of a file to the wrong place. When this happens, the same credentials are used and the server name is the same."},"relatedVulnerabilities":[{"id":"CVE-2026-5773","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-07","epss":0.00657,"percentile":0.49868}],"urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42015","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42015","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42015","date":"2026-10-07","epss":0.0092,"percentile":0.59039}],"risk":0.4738,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42015","description":"A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts."},"relatedVulnerabilities":[{"id":"CVE-2026-42015","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42015","date":"2026-10-07","epss":0.0092,"percentile":0.59039}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42015","https://bugzilla.redhat.com/show_bug.cgi?id=2467678","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42015","description":"A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5942","versionConstraint":">=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5942","fix":{"state":"fixed","versions":["1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-07","epss":0.0063,"percentile":0.48542}],"risk":0.47250000000000003,"urls":["https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/786345","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-46600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-07","epss":0.0063,"percentile":0.48542}],"urls":["https://go.dev/cl/786345","https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5942"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46600","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"< 2.41-12+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"fixed","versions":["2.41-12+deb13u2"],"available":[{"date":"2026-03-16","kind":"first-observed","version":"2.41-12+deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-07","epss":0.00627,"percentile":0.48418}],"risk":0.47025,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-07","epss":0.00627,"percentile":0.48418}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"9624b8abfaf8a472","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.3&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status.d/zlib1g","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/zlib1g","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/zlib1g.md5sums","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/var/lib/dpkg/status.d/zlib1g.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-07","epss":0.00592,"percentile":0.46608}],"risk":0.46768,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-07","epss":0.00592,"percentile":0.46608}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-07","epss":0.00622,"percentile":0.48158}],"risk":0.46649999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.  Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.  CWE: CWE-405: Asymmetric Resource Consumption (Amplification)  Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.  Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.  An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.  FIPS impact: no  No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.  OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.  Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr  This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.  -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-07","epss":0.00622,"percentile":0.48158}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15742","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15742","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15742","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-15742","date":"2026-10-07","epss":0.00555,"percentile":0.44523}],"risk":0.45232500000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15742","description":"Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal().  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-15742","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15742","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-15742","date":"2026-10-07","epss":0.00555,"percentile":0.44523}],"urls":["https://www.postgresql.org/support/security/CVE-2026-15742/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15742","description":"Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal().  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6479","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6479","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6479","cwe":"CWE-674","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6479","date":"2026-10-07","epss":0.00595,"percentile":0.46786}],"risk":0.44625000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6479","description":"Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service.  If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6479","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6479","cwe":"CWE-674","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6479","date":"2026-10-07","epss":0.00595,"percentile":0.46786}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6479/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6479","description":"Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service.  If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42013","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42013","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42013","date":"2026-10-07","epss":0.00564,"percentile":0.45103}],"risk":0.44273999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42013","description":"A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks."},"relatedVulnerabilities":[{"id":"CVE-2026-42013","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42013","date":"2026-10-07","epss":0.00564,"percentile":0.45103}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42013","https://bugzilla.redhat.com/show_bug.cgi?id=2467448","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42013","description":"A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6478","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6478","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6478","cwe":"CWE-385","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6478","cwe":"CWE-385","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6478","date":"2026-10-07","epss":0.00558,"percentile":0.44736}],"risk":0.4380299999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6478","description":"Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate.  This does not affect scram-sha-256 passwords, the default in all supported releases.  However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6478","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6478","cwe":"CWE-385","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6478","cwe":"CWE-385","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6478","date":"2026-10-07","epss":0.00558,"percentile":0.44736}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6478/","https://access.redhat.com/errata/RHSA-2026:21182","https://access.redhat.com/errata/RHSA-2026:22878","https://access.redhat.com/errata/RHSA-2026:26181","https://access.redhat.com/errata/RHSA-2026:26203","https://access.redhat.com/errata/RHSA-2026:26204","https://access.redhat.com/errata/RHSA-2026:26524","https://access.redhat.com/errata/RHSA-2026:26525","https://access.redhat.com/errata/RHSA-2026:26561","https://access.redhat.com/errata/RHSA-2026:27718","https://access.redhat.com/errata/RHSA-2026:27738","https://access.redhat.com/errata/RHSA-2026:27741","https://access.redhat.com/errata/RHSA-2026:27742","https://access.redhat.com/errata/RHSA-2026:27743","https://access.redhat.com/errata/RHSA-2026:28037","https://access.redhat.com/errata/RHSA-2026:28143","https://access.redhat.com/errata/RHSA-2026:28208","https://access.redhat.com/errata/RHSA-2026:28999","https://access.redhat.com/errata/RHSA-2026:29212","https://access.redhat.com/errata/RHSA-2026:29815","https://access.redhat.com/errata/RHSA-2026:29904","https://access.redhat.com/errata/RHSA-2026:29953","https://access.redhat.com/errata/RHSA-2026:32983","https://access.redhat.com/errata/RHSA-2026:32994","https://access.redhat.com/errata/RHSA-2026:33441","https://access.redhat.com/errata/RHSA-2026:33497","https://access.redhat.com/errata/RHSA-2026:34043","https://access.redhat.com/errata/RHSA-2026:34362","https://access.redhat.com/errata/RHSA-2026:34363","https://access.redhat.com/errata/RHSA-2026:35880","https://access.redhat.com/errata/RHSA-2026:42555","https://access.redhat.com/errata/RHSA-2026:44420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:49521","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-6478","https://bugzilla.redhat.com/show_bug.cgi?id=2477447","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6478.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6478","description":"Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate.  This does not affect scram-sha-256 passwords, the default in all supported releases.  However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-07","epss":0.00568,"percentile":0.45287}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-07","epss":0.00568,"percentile":0.45286}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42011","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42011","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42011","date":"2026-10-07","epss":0.0057,"percentile":0.45391}],"risk":0.42465,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42011","description":"A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems."},"relatedVulnerabilities":[{"id":"CVE-2026-42011","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42011","date":"2026-10-07","epss":0.0057,"percentile":0.45391}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42011","https://bugzilla.redhat.com/show_bug.cgi?id=2467437","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42011","description":"A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66035","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66035","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66035","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66035","date":"2026-10-07","epss":0.00551,"percentile":0.44312}],"risk":0.4187600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66035","description":"libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication."},"relatedVulnerabilities":[{"id":"CVE-2026-66035","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66035","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66035","date":"2026-10-07","epss":0.00551,"percentile":0.44312}],"urls":["https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4","https://github.com/libssh2/libssh2/pull/2198","https://www.vulncheck.com/advisories/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66035","description":"libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-07","epss":0.0075,"percentile":0.53526}],"risk":0.40875,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second proxy.  This can happen when the following conditions are true:  1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first proxy (using say `http://`), curl is asked to follow    a redirect to a URL using another scheme (say `https://`), accessed using a    second, different, proxy"},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-07","epss":0.0075,"percentile":0.53526}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14819","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-14819","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-14819","date":"2026-10-07","epss":0.00756,"percentile":0.53731}],"risk":0.38934,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14819","description":"When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not."},"relatedVulnerabilities":[{"id":"CVE-2025-14819","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-14819","date":"2026-10-07","epss":0.00756,"percentile":0.53731}],"urls":["https://curl.se/docs/CVE-2025-14819.html","https://curl.se/docs/CVE-2025-14819.json","http://www.openwall.com/lists/oss-security/2026/01/07/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14819","description":"When doing TLS related transfers with reused easy or multi handles and\naltering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6471","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6471","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.2,"impactScore":5.9,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6471","cwe":"CWE-862","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6471","date":"2026-10-07","epss":0.00528,"percentile":0.42889}],"risk":0.38808,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6471","description":"Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin.  This in turn runs arbitrary code as that account.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6471","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.2,"impactScore":5.9,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6471","cwe":"CWE-862","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6471","date":"2026-10-07","epss":0.00528,"percentile":0.42889}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6471/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6471","description":"Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin.  This in turn runs arbitrary code as that account.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15741","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15741","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15741","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-15741","date":"2026-10-07","epss":0.00466,"percentile":0.38322}],"risk":0.37979,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15741","description":"SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition.  Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \\sf, and any similar usage in non-core tools.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-15741","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15741","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-15741","date":"2026-10-07","epss":0.00466,"percentile":0.38322}],"urls":["https://www.postgresql.org/support/security/CVE-2026-15741/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15741","description":"SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition.  Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \\sf, and any similar usage in non-core tools.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14662","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14662","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14662","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14662","date":"2026-10-07","epss":0.0046,"percentile":0.3782}],"risk":0.3749,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14662","description":"Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs.  This may execute arbitrary code as the operating system user running the database.  These types are typically sourced from application logic, not taken from the application's user.  Hence, application users attacking the database, through the application as a conduit, are unlikely.  CVE-2026-6473 had fixed similar problems.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14662","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14662","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14662","date":"2026-10-07","epss":0.0046,"percentile":0.3782}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14662/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14662","description":"Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs.  This may execute arbitrary code as the operating system user running the database.  These types are typically sourced from application logic, not taken from the application's user.  Hence, application users attacking the database, through the application as a conduit, are unlikely.  CVE-2026-6473 had fixed similar problems.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"< 2.41-12+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"fixed","versions":["2.41-12+deb13u2"],"available":[{"date":"2026-03-16","kind":"first-observed","version":"2.41-12+deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-07","epss":0.00499,"percentile":0.40763}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-07","epss":0.00499,"percentile":0.40763}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15661","versionConstraint":"< 1.11.1-1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15661","fix":{"state":"fixed","versions":["1.11.1-1+deb13u1"],"available":[{"date":"2026-06-25","kind":"advisory","version":"1.11.1-1+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15661","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2025-15661","date":"2026-10-07","epss":0.00648,"percentile":0.49438}],"risk":0.3726,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6365-1","link":"https://security-tracker.debian.org/tracker/DSA-6365-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15661","description":"libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation."},"relatedVulnerabilities":[{"id":"CVE-2025-15661","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15661","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2025-15661","date":"2026-10-07","epss":0.00648,"percentile":0.49438}],"urls":["https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d","https://github.com/libssh2/libssh2/pull/1705","https://github.com/libssh2/libssh2/pull/1717","https://www.vulncheck.com/advisories/libssh2-heap-buffer-over-read-via-sftp-symlink-in-sftp-c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15661","description":"libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 2.41-12+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["2.41-12+deb13u4"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"2.41-12+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-07","epss":0.00493,"percentile":0.40387}],"risk":0.36975,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.  A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-07","epss":0.00493,"percentile":0.40387}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66032","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66032","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66032","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66032","date":"2026-10-07","epss":0.00448,"percentile":0.36929}],"risk":0.3628799999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66032","description":"libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites."},"relatedVulnerabilities":[{"id":"CVE-2026-66032","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66032","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66032","date":"2026-10-07","epss":0.00448,"percentile":0.36929}],"urls":["https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0","https://github.com/libssh2/libssh2/pull/2180","https://www.vulncheck.com/advisories/libssh2-double-free-heap-corruption-via-sftp-open"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66032","description":"libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6477","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6477","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6477","cwe":"CWE-242","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6477","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6477","date":"2026-10-07","epss":0.00454,"percentile":0.3743}],"risk":0.36093000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6477","description":"Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response.  Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size.  Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6477","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6477","cwe":"CWE-242","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6477","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6477","date":"2026-10-07","epss":0.00454,"percentile":0.3743}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6477/","https://access.redhat.com/errata/RHSA-2026:21182","https://access.redhat.com/errata/RHSA-2026:22878","https://access.redhat.com/errata/RHSA-2026:26181","https://access.redhat.com/errata/RHSA-2026:26203","https://access.redhat.com/errata/RHSA-2026:26204","https://access.redhat.com/errata/RHSA-2026:26524","https://access.redhat.com/errata/RHSA-2026:26525","https://access.redhat.com/errata/RHSA-2026:26561","https://access.redhat.com/errata/RHSA-2026:27718","https://access.redhat.com/errata/RHSA-2026:27738","https://access.redhat.com/errata/RHSA-2026:27741","https://access.redhat.com/errata/RHSA-2026:27742","https://access.redhat.com/errata/RHSA-2026:27743","https://access.redhat.com/errata/RHSA-2026:28037","https://access.redhat.com/errata/RHSA-2026:28143","https://access.redhat.com/errata/RHSA-2026:28208","https://access.redhat.com/errata/RHSA-2026:28999","https://access.redhat.com/errata/RHSA-2026:29212","https://access.redhat.com/errata/RHSA-2026:29815","https://access.redhat.com/errata/RHSA-2026:29904","https://access.redhat.com/errata/RHSA-2026:29953","https://access.redhat.com/errata/RHSA-2026:32983","https://access.redhat.com/errata/RHSA-2026:32994","https://access.redhat.com/errata/RHSA-2026:33441","https://access.redhat.com/errata/RHSA-2026:33497","https://access.redhat.com/errata/RHSA-2026:34043","https://access.redhat.com/errata/RHSA-2026:34362","https://access.redhat.com/errata/RHSA-2026:34363","https://access.redhat.com/errata/RHSA-2026:35880","https://access.redhat.com/errata/RHSA-2026:42555","https://access.redhat.com/errata/RHSA-2026:44308","https://access.redhat.com/errata/RHSA-2026:44391","https://access.redhat.com/errata/RHSA-2026:44420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:47090","https://access.redhat.com/errata/RHSA-2026:49521","https://access.redhat.com/errata/RHSA-2026:49908","https://access.redhat.com/errata/RHSA-2026:49909","https://access.redhat.com/errata/RHSA-2026:50779","https://access.redhat.com/errata/RHSA-2026:50863","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-6477","https://bugzilla.redhat.com/show_bug.cgi?id=2477442","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6477.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6477","description":"Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response.  Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size.  Because both the \\lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42012","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42012","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42012","date":"2026-10-07","epss":0.00487,"percentile":0.39963}],"risk":0.35551000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42012","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-42012","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42012","date":"2026-10-07","epss":0.00487,"percentile":0.39963}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42012","https://bugzilla.redhat.com/show_bug.cgi?id=2467441","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42012","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14670","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14670","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14670","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14670","date":"2026-10-07","epss":0.00436,"percentile":0.35795}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14670","description":"Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14670","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14670","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14670","date":"2026-10-07","epss":0.00436,"percentile":0.35795}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14670/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14670","description":"Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14664","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14664","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14664","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14664","date":"2026-10-07","epss":0.00436,"percentile":0.35794}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14664","description":"Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation.  This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14664","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14664","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14664","date":"2026-10-07","epss":0.00436,"percentile":0.35794}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14664/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14664","description":"Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation.  This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"46230cf5226e2e82","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.3&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libldap2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libldap2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-17740","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-07","epss":0.07022,"percentile":0.94013}],"risk":0.3511,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."},"relatedVulnerabilities":[{"id":"CVE-2017-17740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-07","epss":0.07022,"percentile":0.94013}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14524","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-14524","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-07","epss":0.0068,"percentile":0.50899}],"risk":0.3502,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host."},"relatedVulnerabilities":[{"id":"CVE-2025-14524","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-07","epss":0.0068,"percentile":0.50899}],"urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19385","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19385","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19385","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-19385","date":"2026-10-07","epss":0.00427,"percentile":0.34881}],"risk":0.34800500000000006,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19385","description":"Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19385","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19385","cwe":"CWE-122","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-19385","date":"2026-10-07","epss":0.00427,"percentile":0.34881}],"urls":["https://www.postgresql.org/support/security/CVE-2026-19385/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19385","description":"Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14671","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14671","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14671","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14671","date":"2026-10-07","epss":0.00423,"percentile":0.3456}],"risk":0.344745,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14671","description":"Type confusion in PostgreSQL module \"refint\" allows an object creator to execute arbitrary code as the operating system user running the database.  The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject \"refint: Remove plan cache.\", without a CVE number.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14671","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14671","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14671","date":"2026-10-07","epss":0.00423,"percentile":0.3456}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14671/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14671","description":"Type confusion in PostgreSQL module \"refint\" allows an object creator to execute arbitrary code as the operating system user running the database.  The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject \"refint: Remove plan cache.\", without a CVE number.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14677","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14677","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14677","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14677","date":"2026-10-07","epss":0.00423,"percentile":0.3456}],"risk":0.344745,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14677","description":"Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies.  This may execute arbitrary code as the operating system user running the database.  CVE-2026-6473 had fixed similar problems.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14677","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14677","cwe":"CWE-190","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14677","date":"2026-10-07","epss":0.00423,"percentile":0.3456}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14677/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14677","description":"Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies.  This may execute arbitrary code as the operating system user running the database.  CVE-2026-6473 had fixed similar problems.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14680","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14680","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14680","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14680","date":"2026-10-07","epss":0.00423,"percentile":0.3456}],"risk":0.344745,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14680","description":"Type confusion with PostgreSQL \"internal\" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type.  Type \"internal\" represents a class of mutually-incompatible data structures not intended for access from SQL.  The system intended to prevent such function calls, but this prevention had gaps.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14680","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14680","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14680","date":"2026-10-07","epss":0.00423,"percentile":0.3456}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14680/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14680","description":"Type confusion with PostgreSQL \"internal\" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type.  Type \"internal\" represents a class of mutually-incompatible data structures not intended for access from SQL.  The system intended to prevent such function calls, but this prevention had gaps.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14831","versionConstraint":"< 3.8.9-3+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-14831","fix":{"state":"fixed","versions":["3.8.9-3+deb13u2"],"available":[{"date":"2026-02-18","kind":"advisory","version":"3.8.9-3+deb13u2"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14831","cwe":"CWE-407","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14831","date":"2026-10-07","epss":0.00666,"percentile":0.50262}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6140-1","link":"https://security-tracker.debian.org/tracker/DSA-6140-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14831","description":"A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs)."},"relatedVulnerabilities":[{"id":"CVE-2025-14831","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14831","cwe":"CWE-407","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14831","date":"2026-10-07","epss":0.00666,"percentile":0.50262}],"urls":["https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:3477","https://access.redhat.com/errata/RHSA-2026:4188","https://access.redhat.com/errata/RHSA-2026:4655","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:5585","https://access.redhat.com/errata/RHSA-2026:5606","https://access.redhat.com/errata/RHSA-2026:6618","https://access.redhat.com/errata/RHSA-2026:6630","https://access.redhat.com/errata/RHSA-2026:6737","https://access.redhat.com/errata/RHSA-2026:6738","https://access.redhat.com/errata/RHSA-2026:7329","https://access.redhat.com/errata/RHSA-2026:7335","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/security/cve/CVE-2025-14831","https://bugzilla.redhat.com/show_bug.cgi?id=2423177","https://gitlab.com/gnutls/gnutls/-/issues/1773","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14831","description":"A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs)."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58050","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58050","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58050","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58050","date":"2026-10-07","epss":0.00444,"percentile":0.36603}],"risk":0.3330000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58050","description":"libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client."},"relatedVulnerabilities":[{"id":"CVE-2026-58050","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58050","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58050","date":"2026-10-07","epss":0.00444,"percentile":0.36603}],"urls":["https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc","https://github.com/libssh2/libssh2/blob/master/src/publickey.c","https://www.vulncheck.com/advisories/libssh2-integer-overflow-in-publickey-subsystem-attribute-allocation"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58050","description":"libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-07","epss":0.00588,"percentile":0.46391}],"risk":0.32046,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.  Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack.  This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.     The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.  FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-07","epss":0.00588,"percentile":0.46391}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0861","versionConstraint":"< 2.41-12+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-0861","fix":{"state":"fixed","versions":["2.41-12+deb13u2"],"available":[{"date":"2026-03-16","kind":"first-observed","version":"2.41-12+deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0861","cwe":"CWE-190","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0861","date":"2026-10-07","epss":0.00392,"percentile":0.31187}],"risk":0.31164000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-0861","description":"Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.  Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc.  Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments."},"relatedVulnerabilities":[{"id":"CVE-2026-0861","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0861","cwe":"CWE-190","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0861","date":"2026-10-07","epss":0.00392,"percentile":0.31187}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33796","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0001","http://www.openwall.com/lists/oss-security/2026/01/16/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0861","description":"Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.\n\nNote that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc.\n\nTypically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66034","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66034","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66034","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66034","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66034","date":"2026-10-07","epss":0.00402,"percentile":0.32368}],"risk":0.30552,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66034","description":"libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region."},"relatedVulnerabilities":[{"id":"CVE-2026-66034","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66034","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-66034","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66034","date":"2026-10-07","epss":0.00402,"percentile":0.32368}],"urls":["https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9","https://github.com/libssh2/libssh2/pull/2202","https://www.vulncheck.com/advisories/libssh2-heap-out-of-bounds-read-via-publickey-subsystem"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66034","description":"libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-31789","versionConstraint":"< 3.5.5-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"fixed","versions":["3.5.5-1~deb13u2"],"available":[{"date":"2026-04-07","kind":"advisory","version":"3.5.5-1~deb13u2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-07","epss":0.00325,"percentile":0.2349}],"risk":0.3055,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6201-1","link":"https://security-tracker.debian.org/tracker/DSA-6201-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions such as the Subject Key Identifier (SKID) or Authority Key Identifier (AKID) which are being converted to hex, the size of the buffer needed for the result is calculated as multiplication of the input length by 3. On 32 bit platforms, this multiplication may overflow resulting in the allocation of a smaller buffer and a heap buffer overflow.  Applications and services that print or log contents of untrusted X.509 certificates are vulnerable to this issue. As the certificates would have to have sizes of over 1 Gigabyte, printing or logging such certificates is a fairly unlikely operation and only 32 bit platforms are affected, this issue was assigned Low severity.  The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-31789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-07","epss":0.00325,"percentile":0.2349}],"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7168","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7168","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-07","epss":0.00591,"percentile":0.46567}],"risk":0.304365,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to `proxyB`."},"relatedVulnerabilities":[{"id":"CVE-2026-7168","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-07","epss":0.00591,"percentile":0.46567}],"urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6637","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6637","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6637","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6637","cwe":"CWE-121","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6637","date":"2026-10-07","epss":0.0037,"percentile":0.28809}],"risk":0.30155000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6637","description":"Stack buffer overflow in PostgreSQL module \"refint\" allows an unprivileged database user to execute arbitrary code as the operating system user running the database.  A distinct attack is possible if the application declares a user-controlled column as a \"refint\" cascade primary key and facilitates user-controlled updates to that column.  In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6637","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6637","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-6637","cwe":"CWE-121","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6637","date":"2026-10-07","epss":0.0037,"percentile":0.28809}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6637/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6637","description":"Stack buffer overflow in PostgreSQL module \"refint\" allows an unprivileged database user to execute arbitrary code as the operating system user running the database.  A distinct attack is possible if the application declares a user-controlled column as a \"refint\" cascade primary key and facilitates user-controlled updates to that column.  In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-07","epss":0.0055,"percentile":0.44257}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-07","epss":0.0055,"percentile":0.44257}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"b2c2bc2cb57ca2ec","cpes":["cpe:2.3:a:liblzma5:liblzma5:5.8.1-1:*:*:*:*:*:*:*"],"name":"liblzma5","purl":"pkg:deb/debian/liblzma5@5.8.1-1?arch=amd64&distro=debian-13.3&upstream=xz-utils","type":"deb","version":"5.8.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/liblzma5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/liblzma5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"xz-utils"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.8.1-1+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34743","versionConstraint":"< 5.8.1-1+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"xz-utils","version":"5.8.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34743","fix":{"state":"fixed","versions":["5.8.1-1+deb13u1"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"5.8.1-1+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-07","epss":0.00573,"percentile":0.45562}],"risk":0.295095,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34743","description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3."},"relatedVulnerabilities":[{"id":"CVE-2026-34743","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-07","epss":0.00573,"percentile":0.45562}],"urls":["https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87","https://github.com/tukaani-project/xz/releases/tag/v5.8.3","https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv","http://www.openwall.com/lists/oss-security/2026/03/31/13","https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34743","description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-07","epss":0.0051,"percentile":0.41575}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.  An application that first uses Negotiate authentication to a server with `user1:password1` and then does another operation to the same server asking for any authentication method but for `user2:password2` (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1..."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-07","epss":0.0051,"percentile":0.41575}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18408","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18408","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18408","cwe":"CWE-829","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-18408","date":"2026-10-07","epss":0.00355,"percentile":0.27167}],"risk":0.28932500000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18408","description":"Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \\restrict meta-command input expansion.  The fix for CVE-2025-8714 introduced \\restrict and \\unrestrict to block this attack, but \\unrestrict itself was sufficient for an attack.  pg_dumpall is also affected.  pg_restore is affected when used to generate a plain-format dump.  Non-core use of \\restrict would be affected, but we've not identified non-core use.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-18408","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18408","cwe":"CWE-829","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-18408","date":"2026-10-07","epss":0.00355,"percentile":0.27167}],"urls":["https://www.postgresql.org/support/security/CVE-2026-18408/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18408","description":"Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \\restrict meta-command input expansion.  The fix for CVE-2025-8714 introduced \\restrict and \\unrestrict to block this attack, but \\unrestrict itself was sufficient for an attack.  pg_dumpall is also affected.  pg_restore is affected when used to generate a plain-format dump.  Non-core use of \\restrict would be affected, but we've not identified non-core use.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3832","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3832","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-20","kind":"first-observed","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3832","date":"2026-10-07","epss":0.0085,"percentile":0.56889}],"risk":0.28475,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3832","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust."},"relatedVulnerabilities":[{"id":"CVE-2026-3832","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3832","date":"2026-10-07","epss":0.0085,"percentile":0.56889}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-3832","https://bugzilla.redhat.com/show_bug.cgi?id=2445762","https://gitlab.com/gnutls/gnutls/-/issues/1801"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3832","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.5-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-2673","versionConstraint":"< 3.5.5-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-2673","fix":{"state":"fixed","versions":["3.5.5-1~deb13u2"],"available":[{"date":"2026-04-08","kind":"first-observed","version":"3.5.5-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2673","cwe":"CWE-757","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-2673","date":"2026-10-07","epss":0.00489,"percentile":0.40124}],"risk":0.281175,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-2673","description":"Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword.  Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server.  If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported.  As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction).  OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers.  The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included.  The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security.  Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group.  The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'.  No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary.  OpenSSL 3.6 and 3.5 are vulnerable to this issue.  OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.  OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-2673","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2673","cwe":"CWE-757","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-2673","date":"2026-10-07","epss":0.00489,"percentile":0.40124}],"urls":["https://github.com/openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f","https://github.com/openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34","https://openssl-library.org/news/secadv/20260313.txt","http://www.openwall.com/lists/oss-security/2026/03/13/3","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2673","description":"Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected\npreferred key exchange group when its key exchange group configuration includes\nthe default by using the 'DEFAULT' keyword.\n\nImpact summary: A less preferred key exchange may be used even when a more\npreferred group is supported by both client and server, if the group\nwas not included among the client's initial predicated keyshares.\nThis will sometimes be the case with the new hybrid post-quantum groups,\nif the client chooses to defer their use until specifically requested by\nthe server.\n\nIf an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to\ninterpolate the built-in default group list into its own configuration, perhaps\nadding or removing specific elements, then an implementation defect causes the\n'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups\nwere treated as a single sufficiently secure 'tuple', with the server not\nsending a Hello Retry Request (HRR) even when a group in a more preferred tuple\nwas mutually supported.\n\nAs a result, the client and server might fail to negotiate a mutually supported\npost-quantum key agreement group, such as 'X25519MLKEM768', if the client's\nconfiguration results in only 'classical' groups (such as 'X25519' being the\nonly ones in the client's initial keyshare prediction).\n\nOpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS\n1.3 key agreement group on TLS servers.  The old syntax had a single 'flat'\nlist of groups, and treated all the supported groups as sufficiently secure.\nIf any of the keyshares predicted by the client were supported by the server\nthe most preferred among these was selected, even if other groups supported by\nthe client, but not included in the list of predicted keyshares would have been\nmore preferred, if included.\n\nThe new syntax partitions the groups into distinct 'tuples' of roughly\nequivalent security.  Within each tuple the most preferred group included among\nthe client's predicted keyshares is chosen, but if the client supports a group\nfrom a more preferred tuple, but did not predict any corresponding keyshares,\nthe server will ask the client to retry the ClientHello (by issuing a Hello\nRetry Request or HRR) with the most preferred mutually supported group.\n\nThe above works as expected when the server's configuration uses the built-in\ndefault group list, or explicitly defines its own list by directly defining the\nvarious desired groups and group 'tuples'.\n\nNo OpenSSL FIPS modules are affected by this issue, the code in question lies\noutside the FIPS boundary.\n\nOpenSSL 3.6 and 3.5 are vulnerable to this issue.\n\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released.\n\nOpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6464","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6464","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6464","cwe":"CWE-829","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6464","date":"2026-10-07","epss":0.00358,"percentile":0.27479}],"risk":0.27924,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6464","description":"Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection.  If the \"COPY FROM STDIN\" or \"\\copy FROM STDIN\" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands.  \"COPY FROM\" with a filename is unaffected.  The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows.  Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6464","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6464","cwe":"CWE-829","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6464","date":"2026-10-07","epss":0.00358,"percentile":0.27479}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6464/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6464","description":"Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection.  If the \"COPY FROM STDIN\" or \"\\copy FROM STDIN\" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands.  \"COPY FROM\" with a filename is unaffected.  The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows.  Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"7e17eca42542b0ea","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/gcc-14-base","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/var/lib/dpkg/status.d/gcc-14-base","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/gcc-14-base.md5sums","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/var/lib/dpkg/status.d/gcc-14-base.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"aed854e9dcf390b8","cpes":["cpe:2.3:a:libatomic1:libatomic1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libatomic1","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libatomic1","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"aa49ac20455c7644","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/libgcc-s1","layerID":"sha256:c16b2ec4b1493bad1b1de23d659c899e60abb166bda756d02792f0a03ba54a43","accessPath":"/var/lib/dpkg/status.d/libgcc-s1","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libgcc-s1.md5sums","layerID":"sha256:c16b2ec4b1493bad1b1de23d659c899e60abb166bda756d02792f0a03ba54a43","accessPath":"/var/lib/dpkg/status.d/libgcc-s1.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"fa06adc0996a76e7","cpes":["cpe:2.3:a:libgomp1:libgomp1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgomp1","purl":"pkg:deb/debian/libgomp1@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/libgomp1","layerID":"sha256:1f5d28bd51650f429293f7730ede274b81dc0744aa918bc887133c4ad610258c","accessPath":"/var/lib/dpkg/status.d/libgomp1","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/status.d/libgomp1.md5sums","layerID":"sha256:1f5d28bd51650f429293f7730ede274b81dc0744aa918bc887133c4ad610258c","accessPath":"/var/lib/dpkg/status.d/libgomp1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"82b808487e206a4b","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/libstdc++6","layerID":"sha256:6e18ad80f3d64a8cbbcd1ff2e8a0d5ce7282cf664e816b86183a59d30a618e8a","accessPath":"/var/lib/dpkg/status.d/libstdc++6","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/status.d/libstdc++6.md5sums","layerID":"sha256:6e18ad80f3d64a8cbbcd1ff2e8a0d5ce7282cf664e816b86183a59d30a618e8a","accessPath":"/var/lib/dpkg/status.d/libstdc++6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"62f27adbe6fb6265","cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"name":"krb5","purl":"pkg:generic/krb5@1.21.3","type":"binary","version":"1.21.3","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libkrb5.so.3.3","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:mit:kerberos_5:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2007-3149","versionConstraint":"none (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:mit:kerberos_5:1.21.3:*:*:*:*:*:*:*"],"package":{"name":"krb5","version":"1.21.3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2007-3149","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":7.2,"impactScore":10.1,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-3149","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-3149","date":"2026-10-07","epss":0.00363,"percentile":0.28051}],"risk":0.266805,"urls":["http://secunia.com/advisories/26540","http://www.securityfocus.com/archive/1/470739/100/0/threaded","http://www.securityfocus.com/archive/1/470752/100/0/threaded","http://www.securityfocus.com/archive/1/470774/100/0/threaded","http://www.securityfocus.com/bid/24368","http://www.sudo.ws/cgi-bin/cvsweb/sudo/auth/kerb5.c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-3149","description":"sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings.  NOTE: another researcher disputes this vulnerability, stating that the attacker must be \"a user, who can already log into your system, and can already use sudo.\""},"relatedVulnerabilities":[]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6475","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6475","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6475","cwe":"CWE-61","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6475","date":"2026-10-07","epss":0.00324,"percentile":0.23393}],"risk":0.26405999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6475","description":"Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account.  It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries.  Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6475","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6475","cwe":"CWE-61","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6475","date":"2026-10-07","epss":0.00324,"percentile":0.23393}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6475/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6475","description":"Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account.  It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries.  Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-07","epss":0.00512,"percentile":0.41748}],"risk":0.26368,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-07","epss":0.00512,"percentile":0.41748}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"46230cf5226e2e82","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.3&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libldap2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libldap2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2015-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-07","epss":0.05269,"percentile":0.92341}],"risk":0.26345,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."},"relatedVulnerabilities":[{"id":"CVE-2015-3276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-07","epss":0.05269,"percentile":0.92341}],"urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6276","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-07","epss":0.00349,"percentile":0.26421}],"risk":0.26175,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them."},"relatedVulnerabilities":[{"id":"CVE-2026-6276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-07","epss":0.00349,"percentile":0.26421}],"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14668","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14668","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14668","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14668","date":"2026-10-07","epss":0.00334,"percentile":0.24663}],"risk":0.26052000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14668","description":"Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input.  While the calculation loses precision, substantial memory value recovery appears possible.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14668","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14668","cwe":"CWE-843","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14668","date":"2026-10-07","epss":0.00334,"percentile":0.24663}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14668/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14668","description":"Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input.  While the calculation loses precision, substantial memory value recovery appears possible.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3783","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3783","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-07","epss":0.00505,"percentile":0.41201}],"risk":0.260075,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3783","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances.  If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine` or `default` keywords, curl would pass on the bearer token set for the first host also to the second one."},"relatedVulnerabilities":[{"id":"CVE-2026-3783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-07","epss":0.00505,"percentile":0.41201}],"urls":["https://curl.se/docs/CVE-2026-3783.html","https://curl.se/docs/CVE-2026-3783.json","https://hackerone.com/reports/3583983","http://www.openwall.com/lists/oss-security/2026/03/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3783","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3784","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3784","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-07","epss":0.00452,"percentile":0.37209}],"risk":0.25989999999999996,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection."},"relatedVulnerabilities":[{"id":"CVE-2026-3784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-07","epss":0.00452,"percentile":0.37209}],"urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4437","versionConstraint":"< 2.41-12+deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-4437","fix":{"state":"fixed","versions":["2.41-12+deb13u3"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"2.41-12+deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4437","cwe":"CWE-125","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4437","date":"2026-10-07","epss":0.00325,"percentile":0.23514}],"risk":0.24375,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4437","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer."},"relatedVulnerabilities":[{"id":"CVE-2026-4437","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4437","cwe":"CWE-125","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4437","date":"2026-10-07","epss":0.00325,"percentile":0.23514}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34014","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4437","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42767","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42767","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-07","epss":0.00426,"percentile":0.34823}],"risk":0.23217000000000004,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.  Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.  An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.  Applications that process untrusted CMP/CRMF messages may be affected.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42767","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-07","epss":0.00426,"percentile":0.34823}],"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14679","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14679","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14679","cwe":"CWE-121","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14679","date":"2026-10-07","epss":0.00293,"percentile":0.20045}],"risk":0.23000499999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14679","description":"Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count.  The attack can write only 0x0 and 0x1 bytes.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14679","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14679","cwe":"CWE-121","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14679","date":"2026-10-07","epss":0.00293,"percentile":0.20045}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14679/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14679","description":"Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count.  The attack can write only 0x0 and 0x1 bytes.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6638","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6638","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6638","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6638","date":"2026-10-07","epss":0.00275,"percentile":0.18263}],"risk":0.22412500000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6638","description":"SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials.  The attack takes effect at the next REFRESH PUBLICATION.  Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected.  Versions before PostgreSQL 16 are unaffected."},"relatedVulnerabilities":[{"id":"CVE-2026-6638","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":2.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6638","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6638","date":"2026-10-07","epss":0.00275,"percentile":0.18263}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6638/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6638","description":"SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials.  The attack takes effect at the next REFRESH PUBLICATION.  Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected.  Versions before PostgreSQL 16 are unaffected."}]},{"artifact":{"id":"db086fa0f05191a1","cpes":["cpe:2.3:a:libssh2-1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2-1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2_1t64:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2-1t64:1.11.1-1:*:*:*:*:*:*:*","cpe:2.3:a:libssh2:libssh2_1t64:1.11.1-1:*:*:*:*:*:*:*"],"name":"libssh2-1t64","purl":"pkg:deb/debian/libssh2-1t64@1.11.1-1?arch=amd64&distro=debian-13.3&upstream=libssh2","type":"deb","version":"1.11.1-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libssh2-1t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssh2-1t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.1-1+deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58051","versionConstraint":"< 1.11.1-1+deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libssh2","version":"1.11.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58051","fix":{"state":"fixed","versions":["1.11.1-1+deb13u2"],"available":[{"date":"2026-09-13","kind":"first-observed","version":"1.11.1-1+deb13u2"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58051","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58051","date":"2026-10-07","epss":0.00277,"percentile":0.18409}],"risk":0.21883000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58051","description":"libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client."},"relatedVulnerabilities":[{"id":"CVE-2026-58051","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58051","cwe":"CWE-908","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58051","date":"2026-10-07","epss":0.00277,"percentile":0.18409}],"urls":["https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc","https://github.com/libssh2/libssh2/blob/master/src/publickey.c","https://www.vulncheck.com/advisories/libssh2-free-of-uninitialized-pointer-in-publickey-list-cleanup"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58051","description":"libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client."}]},{"artifact":{"id":"9522138d3133b057","cpes":["cpe:2.3:a:otel:sdk\\/log:v0.19.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/sdk/log","purl":"pkg:golang/go.opentelemetry.io/otel/sdk/log@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.21.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hjf4-fphr-2h65","versionConstraint":"<0.21.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/sdk/log","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-hjf4-fphr-2h65","fix":{"state":"fixed","versions":["0.21.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"0.21.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81872","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81872","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81872","date":"2026-10-07","epss":0.00383,"percentile":0.30196}],"risk":0.216395,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hjf4-fphr-2h65","https://nvd.nist.gov/vuln/detail/CVE-2026-81872","https://github.com/open-telemetry/opentelemetry-go/issues/6797","https://github.com/open-telemetry/opentelemetry-go/pull/8620","https://github.com/open-telemetry/opentelemetry-go/commit/ba71b09e6ed272e93a669aeaec1e98b1df4cc582","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/log/v0.21.0"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hjf4-fphr-2h65","description":"OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full"},"relatedVulnerabilities":[{"id":"CVE-2026-81872","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81872","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81872","cwe":"CWE-834","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81872","date":"2026-10-07","epss":0.00383,"percentile":0.30196}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/ba71b09e6ed272e93a669aeaec1e98b1df4cc582","https://github.com/open-telemetry/opentelemetry-go/issues/6797","https://github.com/open-telemetry/opentelemetry-go/pull/8620","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/log/v0.21.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hjf4-fphr-2h65"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81872","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer while the exporter is backpressured. NewBatchingProcessor wraps the exporter with newBufferExporter(exporter, 1), and the poll loop calls queue.TryDequeue and bufferExporter.EnqueueExport before immediately signaling pollTrigger whenever the queue remains at or above batchSize. Because a failed nonblocking EnqueueExport leaves the queue length unchanged, the processor repeatedly retries without waiting for its ticker, exhausting CPU and degrading or denying service in the embedding process. This issue is fixed in version 0.21.0."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5419","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5419","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5419","date":"2026-10-07","epss":0.0063,"percentile":0.4852}],"risk":0.21105,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5419","description":"A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5419","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5419","date":"2026-10-07","epss":0.0063,"percentile":0.4852}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5419","https://bugzilla.redhat.com/show_bug.cgi?id=2467686","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5419","description":"A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6476","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6476","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.2,"impactScore":5.9,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6476","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6476","date":"2026-10-07","epss":0.00287,"percentile":0.19425}],"risk":0.21094500000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6476","description":"SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser.  The attack takes effect when pg_createsubscriber next runs.  Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected.  Versions before PostgreSQL 17 are unaffected."},"relatedVulnerabilities":[{"id":"CVE-2026-6476","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.2,"impactScore":5.9,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6476","cwe":"CWE-89","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6476","date":"2026-10-07","epss":0.00287,"percentile":0.19425}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6476/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6476","description":"SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser.  The attack takes effect when pg_createsubscriber next runs.  Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected.  Versions before PostgreSQL 17 are unaffected."}]},{"artifact":{"id":"6cb50182e88e1d92","cpes":["cpe:2.3:a:grafana:loki\\/v3:v3.0.0-20260917133136-09e6ce2ff1bd:*:*:*:*:*:*:*"],"name":"github.com/grafana/loki/v3","purl":"pkg:golang/github.com/grafana/loki/v3@v3.0.0-20260917133136-09e6ce2ff1bd","type":"go-module","version":"v3.0.0-20260917133136-09e6ce2ff1bd","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goBuildSettings":[{"key":"-buildmode","value":"c-shared"},{"key":"-compiler","value":"gc"},{"key":"-tags","value":"netgo"},{"key":"-trimpath","value":"true"},{"key":"CGO_ENABLED","value":"1"},{"key":"GOARCH","value":"amd64"},{"key":"GOOS","value":"linux"},{"key":"GOAMD64","value":"v1"},{"key":"vcs","value":"git"},{"key":"vcs.revision","value":"09e6ce2ff1bdc19763a10265b870c86f51c98655"},{"key":"vcs.time","value":"2026-09-17T13:31:36Z"},{"key":"vcs.modified","value":"false"}],"goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.6.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-497x-rrr9-68jp","versionConstraint":"<3.6.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/grafana/loki/v3","version":"v3.0.0-20260917133136-09e6ce2ff1bd"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-497x-rrr9-68jp","fix":{"state":"fixed","versions":["3.6.4"],"available":[{"date":"2026-04-17","kind":"first-observed","version":"3.6.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21726","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-21726","date":"2026-10-07","epss":0.00409,"percentile":0.33081}],"risk":0.210635,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-21726","https://grafana.com/security/security-advisories/cve-2026-21726"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-497x-rrr9-68jp","description":"Grafana Loki Path Traversal - CVE-2021-36156 Bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-21726","cvss":[{"type":"Secondary","source":"security@grafana.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21726","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-21726","date":"2026-10-07","epss":0.00409,"percentile":0.33081}],"urls":["https://grafana.com/security/security-advisories/cve-2026-21726"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-21726","description":"The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}\n\nThanks to Prasanth Sundararajan for reporting this vulnerability."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.5.7-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.5.7-1~deb13u2"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.5.7-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-07","epss":0.00232,"percentile":0.12857}],"risk":0.20996,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6465-1","link":"https://security-tracker.debian.org/tracker/DSA-6465-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.  Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.  CWE: CWE-354 (Improper Validation of Integrity Check Value)  Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.  FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module."},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-07","epss":0.00232,"percentile":0.12857}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4873","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-07","epss":0.00359,"percentile":0.27554}],"risk":0.195655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted."},"relatedVulnerabilities":[{"id":"CVE-2026-4873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-07","epss":0.00359,"percentile":0.27554}],"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"risk":0.19197999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7e17eca42542b0ea","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/gcc-14-base","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/var/lib/dpkg/status.d/gcc-14-base","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/gcc-14-base.md5sums","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/var/lib/dpkg/status.d/gcc-14-base.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"aed854e9dcf390b8","cpes":["cpe:2.3:a:libatomic1:libatomic1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libatomic1","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libatomic1","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"aa49ac20455c7644","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/libgcc-s1","layerID":"sha256:c16b2ec4b1493bad1b1de23d659c899e60abb166bda756d02792f0a03ba54a43","accessPath":"/var/lib/dpkg/status.d/libgcc-s1","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libgcc-s1.md5sums","layerID":"sha256:c16b2ec4b1493bad1b1de23d659c899e60abb166bda756d02792f0a03ba54a43","accessPath":"/var/lib/dpkg/status.d/libgcc-s1.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"fa06adc0996a76e7","cpes":["cpe:2.3:a:libgomp1:libgomp1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgomp1","purl":"pkg:deb/debian/libgomp1@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/libgomp1","layerID":"sha256:1f5d28bd51650f429293f7730ede274b81dc0744aa918bc887133c4ad610258c","accessPath":"/var/lib/dpkg/status.d/libgomp1","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/status.d/libgomp1.md5sums","layerID":"sha256:1f5d28bd51650f429293f7730ede274b81dc0744aa918bc887133c4ad610258c","accessPath":"/var/lib/dpkg/status.d/libgomp1.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"82b808487e206a4b","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.3&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status.d/libstdc++6","layerID":"sha256:6e18ad80f3d64a8cbbcd1ff2e8a0d5ce7282cf664e816b86183a59d30a618e8a","accessPath":"/var/lib/dpkg/status.d/libstdc++6","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/status.d/libstdc++6.md5sums","layerID":"sha256:6e18ad80f3d64a8cbbcd1ff2e8a0d5ce7282cf664e816b86183a59d30a618e8a","accessPath":"/var/lib/dpkg/status.d/libstdc++6.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:7db505d90756626f425c6c5468eca565c82f589b144ecaa4f411ad9bbf79e614","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"fa925028c58e5356","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.64.0-1.1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.64.0-1.1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/debian/libnghttp2-14@1.64.0-1.1?arch=amd64&distro=debian-13.3&upstream=nghttp2","type":"deb","version":"1.64.0-1.1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libnghttp2-14","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libnghttp2-14","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"nghttp2","version":"1.64.0-1.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-07","epss":0.00319,"percentile":0.22798}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-58055","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-07","epss":0.00319,"percentile":0.22798}],"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"ddaacf27cdbe0c91","cpes":["cpe:2.3:a:golang:go:1.26.5:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.26.5","type":"go-module","version":"go1.26.5","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.26.5"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-07","epss":0.0031,"percentile":0.21792}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-07","epss":0.0031,"percentile":0.21792}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.41-12+deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4438","versionConstraint":"< 2.41-12+deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-4438","fix":{"state":"fixed","versions":["2.41-12+deb13u3"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"2.41-12+deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4438","cwe":"CWE-20","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-4438","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4438","date":"2026-10-07","epss":0.00316,"percentile":0.22502}],"risk":0.16432,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4438","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification."},"relatedVulnerabilities":[{"id":"CVE-2026-4438","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4438","cwe":"CWE-20","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-4438","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4438","date":"2026-10-07","epss":0.00316,"percentile":0.22502}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34015","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4438","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6470","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6470","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6470","cwe":"CWE-862","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6470","date":"2026-10-07","epss":0.00329,"percentile":0.23996}],"risk":0.15298499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6470","description":"Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type.  Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6470","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6470","cwe":"CWE-862","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6470","date":"2026-10-07","epss":0.00329,"percentile":0.23996}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6470/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6470","description":"Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type.  Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1965","versionConstraint":"< 8.14.1-2+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-1965","fix":{"state":"fixed","versions":["8.14.1-2+deb13u4"],"available":[{"date":"2026-07-12","kind":"first-observed","version":"8.14.1-2+deb13u4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-07","epss":0.00259,"percentile":0.1615}],"risk":0.148925,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates *connections* and not *requests*, contrary to how HTTP is designed to work.  An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with `user1:password1` and then does another operation to the same server also using Negotiate but with `user2:password2` (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...  The set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.  Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: `CURLOPT_FRESH_CONNECT`, `CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the curl_multi API)."},"relatedVulnerabilities":[{"id":"CVE-2026-1965","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-07","epss":0.00259,"percentile":0.1615}],"urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API)."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6474","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6474","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6474","cwe":"CWE-134","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6474","date":"2026-10-07","epss":0.0031,"percentile":0.21818}],"risk":0.14414999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6474","description":"Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6474","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6474","cwe":"CWE-134","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6474","date":"2026-10-07","epss":0.0031,"percentile":0.21818}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6474/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6474","description":"Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34181","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-34181","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34181","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34181","date":"2026-10-07","epss":0.00182,"percentile":0.07139}],"risk":0.13559,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-34181","description":"Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery.  Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability.  If a service accepting PKCS#12 files is using passwords for authenticating the received files, the attacker can create unencrypted PKCS#12 files that use PBMAC1 authentication that specifies an HMAC key of only one byte, allowing them to craft a file that will be accepted with a 1 in 256 probability. That would then cause the service to accept a certificate and private key controlled by the attacker.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-34181","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34181","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34181","date":"2026-10-07","epss":0.00182,"percentile":0.07139}],"urls":["https://github.com/openssl/openssl/commit/0300eb9ddce7a0895bf301a4b0c03a9da2313a0f","https://github.com/openssl/openssl/commit/79eb76a937e474bb7610a0a3dc57131dc8dc6610","https://github.com/openssl/openssl/commit/85dcbb3abaa4878af5c8fbbe11bce708fcf984a7","https://github.com/openssl/openssl/commit/ec36f2417c4ddd8cabce4b4a60a3d7a7365f2d81","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34181","description":"Issue Summary: The PKCS#12 file processing fails to perform sufficient input\nvalidation for files that use Password-Based Message Authentication Code 1\n(PBMAC1) integrity mechanism allowing a certificate and private key forgery.\n\nImpact Summary: An attacker impersonating a user can cause a service reading\nPKCS#12 files to accept forged certificates and private keys with a 1 in 256\nprobability.\n\nIf a service accepting PKCS#12 files is using passwords for authenticating\nthe received files, the attacker can create unencrypted PKCS#12 files that\nuse PBMAC1 authentication that specifies an HMAC key of only one byte, allowing\nthem to craft a file that will be accepted with a 1 in 256 probability.\nThat would then cause the service to accept a certificate and private key\ncontrolled by the attacker.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"fix":{"suggestedVersion":"8.14.1-2+deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-13034","versionConstraint":"< 8.14.1-2+deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-13034","fix":{"state":"fixed","versions":["8.14.1-2+deb13u3"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"8.14.1-2+deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13034","date":"2026-10-07","epss":0.00239,"percentile":0.13691}],"risk":0.130255,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-13034","description":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool, curl should check the public key of the server certificate to verify the peer.  This check was skipped in a certain condition that would then make curl allow the connection without performing the proper check, thus not noticing a possible impostor. To skip this check, the connection had to be done with QUIC with ngtcp2 built to use GnuTLS and the user had to explicitly disable the standard certificate verification."},"relatedVulnerabilities":[{"id":"CVE-2025-13034","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13034","date":"2026-10-07","epss":0.00239,"percentile":0.13691}],"urls":["https://curl.se/docs/CVE-2025-13034.html","https://curl.se/docs/CVE-2025-13034.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13034","description":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14672","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14672","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14672","cwe":"CWE-204","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14672","date":"2026-10-07","epss":0.00252,"percentile":0.15253}],"risk":0.12978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14672","description":"Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count.  This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations.  Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected.  Versions before PostgreSQL 16 are unaffected."},"relatedVulnerabilities":[{"id":"CVE-2026-14672","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14672","cwe":"CWE-204","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14672","date":"2026-10-07","epss":0.00252,"percentile":0.15253}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14672/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14672","description":"Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count.  This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations.  Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected.  Versions before PostgreSQL 16 are unaffected."}]},{"artifact":{"id":"46230cf5226e2e82","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.3&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libldap2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libldap2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-15719","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-07","epss":0.02515,"percentile":0.84329}],"risk":0.12575,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."},"relatedVulnerabilities":[{"id":"CVE-2020-15719","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-07","epss":0.02515,"percentile":0.84329}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42769","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42769","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42769","cwe":"CWE-295","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42769","date":"2026-10-07","epss":0.00239,"percentile":0.1368}],"risk":0.12308500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42769","description":"Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response rendered the certificate validation ineffectual, which could lead to escalation of credentials from the Registration Authority (RA) level to the root Certification Authority (root CA) level.  Impact Summary: The Registration Autority could replace the root CA certificate for the CMP clients with an arbitrary root CA certificate.  One of the parts of the Certificate Management Protocol (CMP), specified in RFC 9810, is Root Certification Authority (root CA) key Rollover, which is sent by the server in a message with type 'id-it-rootCaKeyUpdate'. As part of these messages, 'newWithOld' certificate, the new root CA certificate signed with the old root CA key, is provided, and verifying its signature is crucial for transferring the trust from the old CA key to the new one.  The 'id-it-rootCaKeyUpdate' messages are expected to be processed with OSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld' certificate.  A typo in the certificate chain building code led to adding an incorrect certificate ('newWithOld' instead of 'oldRoot') to the certificate chain, rendering the certificate verification process ineffectual (only the issuer name and the algorithm OIDs were verified by other parts of the verification code).  An attacker who already has credentials that satisfy the CMP message protection checks can generate a new key pair and use a crafted self-signed certificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP clients would accept as a new trust anchor.  Significant preconditions for the attack (having valid RA-level credentials) are the reason the issue was assigned Low severity.  The FIPS modules are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42769","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42769","cwe":"CWE-295","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42769","date":"2026-10-07","epss":0.00239,"percentile":0.1368}],"urls":["https://github.com/openssl/openssl/commit/54d0989997e5fc26057009a9782c3441ce3842fb","https://github.com/openssl/openssl/commit/777b363b16fcf2153bb3ded39dc3838713667c44","https://github.com/openssl/openssl/commit/d35cd473a271bf3ce7bf3d32af53217fb83ae92c","https://github.com/openssl/openssl/commit/d531f21c0fe99067a66fc0ff1161ef127f9cd70b","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42769","description":"Issue Summary: An error in the callback used to verify the certificate\nprovided in a Root CA key update Certificate Management Protocol (CMP)\nmessage response rendered the certificate validation ineffectual, which\ncould lead to escalation of credentials from the Registration Authority (RA)\nlevel to the root Certification Authority (root CA) level.\n\nImpact Summary: The Registration Autority could replace the root CA\ncertificate for the CMP clients with an arbitrary root CA certificate.\n\nOne of the parts of the Certificate Management Protocol (CMP), specified in\nRFC 9810, is Root Certification Authority (root CA) key Rollover,\nwhich is sent by the server in a message with type 'id-it-rootCaKeyUpdate'.\nAs part of these messages, 'newWithOld' certificate, the new root CA\ncertificate signed with the old root CA key, is provided, and verifying its\nsignature is crucial for transferring the trust from the old CA key to the\nnew one.\n\nThe 'id-it-rootCaKeyUpdate' messages are expected to be processed with\nOSSL_CMP_get1_rootCaKeyUpdate(), that is expected to verify the 'newWithOld'\ncertificate.  A typo in the certificate chain building code led to adding\nan incorrect certificate ('newWithOld' instead of 'oldRoot') to the\ncertificate chain, rendering the certificate verification process ineffectual\n(only the issuer name and the algorithm OIDs were verified by other parts\nof the verification code).\n\nAn attacker who already has credentials that satisfy the CMP message\nprotection checks can generate a new key pair and use a crafted self-signed\ncertificate in its 'id-it-rootCaKeyUpdate' CMP messages which affected CMP\nclients would accept as a new trust anchor.\n\nSignificant preconditions for the attack (having valid RA-level credentials)\nare the reason the issue was assigned Low severity.\n\nThe FIPS modules are not affected by this issue, as the affected code is\noutside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.10-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6472","versionConstraint":"< 17.10-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6472","fix":{"state":"fixed","versions":["17.10-0+deb13u1"],"available":[{"date":"2026-05-14","kind":"advisory","version":"17.10-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6472","cwe":"CWE-862","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6472","date":"2026-10-07","epss":0.0023,"percentile":0.12704}],"risk":0.1196,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6270-1","link":"https://security-tracker.debian.org/tracker/DSA-6270-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6472","description":"Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types.  That is to say, the victim will execute arbitrary SQL functions of the attacker's choice.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6472","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6472","cwe":"CWE-862","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6472","date":"2026-10-07","epss":0.0023,"percentile":0.12704}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6472/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6472","description":"Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types.  That is to say, the victim will execute arbitrary SQL functions of the attacker's choice.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40225","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40225","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40225","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40225","date":"2026-10-07","epss":0.00208,"percentile":0.09998}],"risk":0.11856,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40225","description":"In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output."},"relatedVulnerabilities":[{"id":"CVE-2026-40225","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40225","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40225","date":"2026-10-07","epss":0.00208,"percentile":0.09998}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-vpfq-8p5f-jcqx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40225","description":"In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output."}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40225","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40225","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40225","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40225","date":"2026-10-07","epss":0.00208,"percentile":0.09998}],"risk":0.11856,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40225","description":"In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output."},"relatedVulnerabilities":[{"id":"CVE-2026-40225","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40225","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40225","date":"2026-10-07","epss":0.00208,"percentile":0.09998}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-vpfq-8p5f-jcqx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40225","description":"In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output."}]},{"artifact":{"id":"41e4f48606917181","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgnutls30t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgnutls30t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.9-3+deb13u4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42014","versionConstraint":"< 3.8.9-3+deb13u4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42014","fix":{"state":"fixed","versions":["3.8.9-3+deb13u4"],"available":[{"date":"2026-05-19","kind":"advisory","version":"3.8.9-3+deb13u4"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42014","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42014","date":"2026-10-07","epss":0.002,"percentile":0.09025}],"risk":0.116,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6281-1","link":"https://security-tracker.debian.org/tracker/DSA-6281-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42014","description":"A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path."},"relatedVulnerabilities":[{"id":"CVE-2026-42014","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42014","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42014","date":"2026-10-07","epss":0.002,"percentile":0.09025}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42014","https://bugzilla.redhat.com/show_bug.cgi?id=2467451","https://gitlab.com/gnutls/gnutls/-/issues/1766","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42014","description":"A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45446","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-45446","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-07","epss":0.00236,"percentile":0.13407}],"risk":0.11564000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-45446","description":"Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages.  Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers.  AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully.  In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value.  When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key.  AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2.  No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-45446","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-07","epss":0.00236,"percentile":0.13407}],"urls":["https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc","https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3","https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85","https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598","https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45446","description":"Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"07dafbbecad1a5a8","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.3&upstream=p11-kit","type":"deb","version":"0.25.5-3","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libp11-kit0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libp11-kit0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13757","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-07","epss":0.00202,"percentile":0.09252}],"risk":0.11312000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."},"relatedVulnerabilities":[{"id":"CVE-2026-13757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-07","epss":0.00202,"percentile":0.09252}],"urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."}]},{"artifact":{"id":"5826072934743d2f","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.11.0-7:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/debian/libgcrypt20@1.11.0-7?arch=amd64&distro=debian-13.3","type":"deb","version":"1.11.0-7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgcrypt20","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgcrypt20","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.11.0-7+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41989","versionConstraint":"< 1.11.0-7+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libgcrypt20","version":"1.11.0-7"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-41989","fix":{"state":"fixed","versions":["1.11.0-7+deb13u1"],"available":[{"date":"2026-05-22","kind":"advisory","version":"1.11.0-7+deb13u1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.2,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41989","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41989","date":"2026-10-07","epss":0.00192,"percentile":0.08103}],"risk":0.11232,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6294-1","link":"https://security-tracker.debian.org/tracker/DSA-6294-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-41989","description":"Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt."},"relatedVulnerabilities":[{"id":"CVE-2026-41989","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.2,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41989","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41989","date":"2026-10-07","epss":0.00192,"percentile":0.08103}],"urls":["https://dev.gnupg.org/T8211","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html","https://www.openwall.com/lists/oss-security/2026/04/21/1","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41989","description":"Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt."}]},{"artifact":{"id":"8600159a8017d0a2","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlplog\\/otlploggrpc:v0.19.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.21.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w34q-cm8f-9c5x","versionConstraint":"<0.21.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w34q-cm8f-9c5x","fix":{"state":"fixed","versions":["0.21.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"0.21.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81871","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81871","cwe":"CWE-923","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81871","date":"2026-10-07","epss":0.00196,"percentile":0.08556}],"risk":0.11073999999999999,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x","https://nvd.nist.gov/vuln/detail/CVE-2026-81871","https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w34q-cm8f-9c5x","description":"OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning"},"relatedVulnerabilities":[{"id":"CVE-2026-81871","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81871","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81871","cwe":"CWE-923","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81871","date":"2026-10-07","epss":0.00196,"percentile":0.08556}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81871","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6469","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6469","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.8,"impactScore":2.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6469","cwe":"CWE-708","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6469","date":"2026-10-07","epss":0.00318,"percentile":0.2272}],"risk":0.10812000000000001,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6469","description":"Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user.  This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership.  It wrongly denies those commands to the prior statistics object owner.  DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-6469","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.8,"impactScore":2.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6469","cwe":"CWE-708","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-6469","date":"2026-10-07","epss":0.00318,"percentile":0.2272}],"urls":["https://www.postgresql.org/support/security/CVE-2026-6469/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6469","description":"Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user.  This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership.  It wrongly denies those commands to the prior statistics object owner.  DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"c6ebcfb78a881f6f","cpes":["cpe:2.3:a:treasuredata:fluent_bit:4.2.3:*:*:*:*:*:*:*"],"name":"fluent-bit","purl":"pkg:github/fluent/fluent-bit@4.2.3","type":"binary","version":"4.2.3","language":"","licenses":[],"locations":[{"path":"/fluent-bit/bin/fluent-bit","layerID":"sha256:1790522d16b9f23f6c6637d798b65cc88edb6c390a08085371e2ec5a10b1a71b","accessPath":"/fluent-bit/bin/fluent-bit","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-29478","versionConstraint":"none (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:treasuredata:fluent_bit:4.2.3:*:*:*:*:*:*:*"],"package":{"name":"fluent-bit","version":"4.2.3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-29478","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-29478","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-29478","date":"2026-10-07","epss":0.00203,"percentile":0.09393}],"risk":0.106575,"urls":["https://github.com/lmarch2/poc/blob/main/fluent-bit/fluent-bit.md"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-29478","description":"An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165."},"relatedVulnerabilities":[]},{"artifact":{"id":"b6ee860d702b8084","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgssapi-krb5-2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgssapi-krb5-2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"52ef833c1503e21a","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libk5crypto3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libk5crypto3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"d4c94f2fc66f3184","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5-3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5-3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"56fc39be304d53f0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5support0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5support0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"4da413accaebc79c","cpes":["cpe:2.3:a:libcap2:libcap2:1\\:2.75-10\\+b3:*:*:*:*:*:*:*"],"name":"libcap2","purl":"pkg:deb/debian/libcap2@1%3A2.75-10%2Bb3?arch=amd64&distro=debian-13.3&upstream=libcap2%401%3A2.75-10","type":"deb","version":"1:2.75-10+b3","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcap2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcap2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libcap2","version":"1:2.75-10"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:2.75-10+deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4878","versionConstraint":"< 1:2.75-10+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libcap2","version":"1:2.75-10+b3"},"namespace":"debian:distro:debian:13"}},{"fix":{"suggestedVersion":"1:2.75-10+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4878","versionConstraint":"< 1:2.75-10+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libcap2","version":"1:2.75-10"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-4878","fix":{"state":"fixed","versions":["1:2.75-10+deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"1:2.75-10+deb13u1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4878","date":"2026-10-07","epss":0.00141,"percentile":0.02966}],"risk":0.102225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4878","description":"A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-4878","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4878","date":"2026-10-07","epss":0.00141,"percentile":0.02966}],"urls":["https://access.redhat.com/errata/RHSA-2026:12423","https://access.redhat.com/errata/RHSA-2026:12441","https://access.redhat.com/errata/RHSA-2026:13285","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:19130","https://access.redhat.com/errata/RHSA-2026:19346","https://access.redhat.com/errata/RHSA-2026:19456","https://access.redhat.com/errata/RHSA-2026:19458","https://access.redhat.com/errata/RHSA-2026:20595","https://access.redhat.com/errata/RHSA-2026:21254","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:22634","https://access.redhat.com/errata/RHSA-2026:22957","https://access.redhat.com/errata/RHSA-2026:23233","https://access.redhat.com/errata/RHSA-2026:23245","https://access.redhat.com/errata/RHSA-2026:24346","https://access.redhat.com/errata/RHSA-2026:25044","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:25181","https://access.redhat.com/errata/RHSA-2026:26542","https://access.redhat.com/errata/RHSA-2026:27998","https://access.redhat.com/errata/RHSA-2026:28887","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:34098","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:7473","https://access.redhat.com/security/cve/CVE-2026-4878","https://bugzilla.redhat.com/show_bug.cgi?id=2447554","https://bugzilla.redhat.com/show_bug.cgi?id=2451615","http://www.openwall.com/lists/oss-security/2026/04/07/14","http://www.openwall.com/lists/oss-security/2026/04/07/4","http://www.openwall.com/lists/oss-security/2026/04/08/9","http://www.openwall.com/lists/oss-security/2026/04/09/5","http://www.openwall.com/lists/oss-security/2026/04/09/6","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4878","description":"A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation."}]},{"artifact":{"id":"9624b8abfaf8a472","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.3&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status.d/zlib1g","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/zlib1g","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/zlib1g.md5sums","layerID":"sha256:e4ba966d7f0527dfe0fcb559e4e18d4da42c4e6beae924719255e0dedb554ed0","accessPath":"/var/lib/dpkg/status.d/zlib1g.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-07","epss":0.00191,"percentile":0.08065}],"risk":0.10027499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-07","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42768","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42768","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-10","kind":"first-observed","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42768","cwe":"CWE-514","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42768","date":"2026-10-07","epss":0.00295,"percentile":0.20288}],"risk":0.098825,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42768","description":"Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME messages and observe the error code and/or decryption output.  Impact summary: The Bleichenbacher-style attack allows an attacker to use the victim's vulnerable application as a way to decrypt or sign messages with the victim's private RSA key.  The attack is possible in 2 variants.  1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without providing the recipient certificate. In this case OpenSSL iterates over every KeyTransRecipientInfo (KTRI) without stopping at the first success.  An attacker who authors a message with two KTRI entries — the first one wrapping a real CEK under the victim's public key, the second with an arbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to get a valid PKCS#1 v1.5 padding if the error code of the application is available.  That is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an adaptive-chosen-ciphertext side channel from which the attacker decrypts any RSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under it.  2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with the recipient certificate, and the recipient is not found, a random key is substituted.  An attacker who authors a message and is able to compare both error code and the result of the decryption, can mount a Bleichenbacher oracle.  We are not aware of any applications that provide a remote attacker an opportunity to mount an attack described in these scenarios. We consider the existence of such application very unlikely, and for this reason this CVE has been evaluated as Low severity.  To avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described in draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit rejection was explicitly disabled.  The implicit rejection mechanism always returns a plaintext value, the symmetric key. This result is deterministic for the ciphertext and the private key.  The length of the decryption result can happen to match the length of the key of the symmetric cipher that was used for the content encryption. When a certificate is not provided, the last RecipientInfo producing a key that looks valid will be used. It may cause getting garbage content on decryption. As a proper way to deal with this a recipient certificate has to be provided to identify the particular RecipientInfo for decryption.  The FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as CMS and S/MIME processing happens outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42768","cwe":"CWE-514","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42768","date":"2026-10-07","epss":0.00295,"percentile":0.20288}],"urls":["https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f","https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d","https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd","https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42768","description":"Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"c6ebcfb78a881f6f","cpes":["cpe:2.3:a:treasuredata:fluent_bit:4.2.3:*:*:*:*:*:*:*"],"name":"fluent-bit","purl":"pkg:github/fluent/fluent-bit@4.2.3","type":"binary","version":"4.2.3","language":"","licenses":[],"locations":[{"path":"/fluent-bit/bin/fluent-bit","layerID":"sha256:1790522d16b9f23f6c6637d798b65cc88edb6c390a08085371e2ec5a10b1a71b","accessPath":"/fluent-bit/bin/fluent-bit","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-29477","versionConstraint":"none (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:treasuredata:fluent_bit:4.2.3:*:*:*:*:*:*:*"],"package":{"name":"fluent-bit","version":"4.2.3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-29477","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.5,"impactScore":4.8,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-29477","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-29477","date":"2026-10-07","epss":0.00181,"percentile":0.0705}],"risk":0.095025,"urls":["https://github.com/lmarch2/poc/blob/main/fluent-bit/fluent-bit.md"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-29477","description":"An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event."},"relatedVulnerabilities":[]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14678","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14678","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14678","cwe":"CWE-126","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14678","date":"2026-10-07","epss":0.00195,"percentile":0.08425}],"risk":0.09067499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14678","description":"Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer.  This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14678","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14678","cwe":"CWE-126","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14678","date":"2026-10-07","epss":0.00195,"percentile":0.08425}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14678/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14678","description":"Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer.  This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18024","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18024","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18024","cwe":"CWE-126","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-18024","date":"2026-10-07","epss":0.00195,"percentile":0.08425}],"risk":0.09067499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18024","description":"Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value.  This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-18024","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18024","cwe":"CWE-126","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-18024","date":"2026-10-07","epss":0.00195,"percentile":0.08425}],"urls":["https://www.postgresql.org/support/security/CVE-2026-18024/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18024","description":"Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value.  This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"5826072934743d2f","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.11.0-7:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/debian/libgcrypt20@1.11.0-7?arch=amd64&distro=debian-13.3","type":"deb","version":"1.11.0-7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgcrypt20","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgcrypt20","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libgcrypt20","version":"1.11.0-7"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-07","epss":0.01777,"percentile":0.77534}],"risk":0.08885000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."},"relatedVulnerabilities":[{"id":"CVE-2018-6829","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-07","epss":0.01777,"percentile":0.77534}],"urls":["https://github.com/weikengchen/attack-on-libgcrypt-elgamal","https://github.com/weikengchen/attack-on-libgcrypt-elgamal/wiki","https://lists.gnupg.org/pipermail/gcrypt-devel/2018-February/004394.html","https://www.oracle.com/security-alerts/cpujan2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4105","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-4105","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-07","epss":0.00149,"percentile":0.03543}],"risk":0.08716499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."},"relatedVulnerabilities":[{"id":"CVE-2026-4105","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-07","epss":0.00149,"percentile":0.03543}],"urls":["https://access.redhat.com/errata/RHSA-2026:7299","https://access.redhat.com/security/cve/CVE-2026-4105","https://bugzilla.redhat.com/show_bug.cgi?id=2447262","https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4105","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-4105","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-07","epss":0.00149,"percentile":0.03543}],"risk":0.08716499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."},"relatedVulnerabilities":[{"id":"CVE-2026-4105","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4105","cwe":"CWE-284","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4105","date":"2026-10-07","epss":0.00149,"percentile":0.03543}],"urls":["https://access.redhat.com/errata/RHSA-2026:7299","https://access.redhat.com/security/cve/CVE-2026-4105","https://bugzilla.redhat.com/show_bug.cgi?id=2447262","https://github.com/systemd/systemd/security/advisories/GHSA-4h6x-r8vx-3862"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4105","description":"A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary commands with root privileges on the host system."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-29111","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-29111","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-29111","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-29111","date":"2026-10-07","epss":0.00166,"percentile":0.05343}],"risk":0.08715,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-29111","description":"systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available."},"relatedVulnerabilities":[{"id":"CVE-2026-29111","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-29111","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-29111","date":"2026-10-07","epss":0.00166,"percentile":0.05343}],"urls":["https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a","https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6","https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412","https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd","https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f","https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f","https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69","https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6","https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c","https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8","https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-29111","description":"systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available."}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-29111","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-29111","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-29111","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-29111","date":"2026-10-07","epss":0.00166,"percentile":0.05343}],"risk":0.08715,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-29111","description":"systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available."},"relatedVulnerabilities":[{"id":"CVE-2026-29111","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-29111","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-29111","date":"2026-10-07","epss":0.00166,"percentile":0.05343}],"urls":["https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a","https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6","https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412","https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd","https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f","https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f","https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69","https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6","https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c","https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8","https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-29111","description":"systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.6-1~deb13u2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42770","versionConstraint":"< 3.5.6-1~deb13u2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42770","fix":{"state":"fixed","versions":["3.5.6-1~deb13u2"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.5.6-1~deb13u2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-07","epss":0.00258,"percentile":0.15987}],"risk":0.08642999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6335-1","link":"https://security-tracker.debian.org/tracker/DSA-6335-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42770","description":"Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership.  Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts.  When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared.  A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack).  The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity.  The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-42770","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-07","epss":0.00258,"percentile":0.15987}],"urls":["https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02","https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb","https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c","https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2","https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42770","description":"Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue."}]},{"artifact":{"id":"07dafbbecad1a5a8","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.3&upstream=p11-kit","type":"deb","version":"0.25.5-3","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libp11-kit0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libp11-kit0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18938","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18938","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-07","epss":0.00152,"percentile":0.03823}],"risk":0.08512000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."},"relatedVulnerabilities":[{"id":"CVE-2026-18938","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-07","epss":0.00152,"percentile":0.03823}],"urls":["https://access.redhat.com/security/cve/CVE-2026-18938","https://bugzilla.redhat.com/show_bug.cgi?id=2478995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"ff0b0009b068d729","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.4-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.4-1~deb13u2?arch=amd64&distro=debian-13.3&upstream=openssl","type":"deb","version":"3.5.4-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status.d/libssl3t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libssl3t64","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libssl3t64.md5sums","layerID":"sha256:a1447d8ccf054f719951bbf62254b6e958908a8ea4eb101c2416acd3e47f8fe2","accessPath":"/var/lib/dpkg/status.d/libssl3t64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openssl","version":"3.5.4-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-07","epss":0.00243,"percentile":0.14241}],"risk":0.08140499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.  Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.  Applications performing SM2 signature generation are affected on all platforms.  FIPS Impact: no SM2 is not a FIPS algorithm."},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-07","epss":0.00243,"percentile":0.14241}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14666","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14666","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14666","cwe":"CWE-1250","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14666","date":"2026-10-07","epss":0.00175,"percentile":0.06429}],"risk":0.0805,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14666","description":"Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse.  Stale policies continue until some other event invalidates the cache or connection termination ends the session.  This permits a user to complete reads and modifications that were recently permitted but now forbidden.  An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14666","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14666","cwe":"CWE-1250","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14666","date":"2026-10-07","epss":0.00175,"percentile":0.06429}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14666/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14666","description":"Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse.  Stale policies continue until some other event invalidates the cache or connection termination ends the session.  This permits a user to complete reads and modifications that were recently permitted but now forbidden.  An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-07","epss":0.00144,"percentile":0.03171}],"risk":0.07128000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.    This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-07","epss":0.00144,"percentile":0.03171}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-07","epss":0.00124,"percentile":0.01877}],"risk":0.07005999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.  Exploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-07","epss":0.00124,"percentile":0.01877}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16241","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-16241","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.8,"impactScore":2.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16241","cwe":"CWE-191","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-16241","date":"2026-10-07","epss":0.00198,"percentile":0.08828}],"risk":0.06731999999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16241","description":"Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix.  The client overwrites a huge memory region with bytes outside attacker knowledge or control.  This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-16241","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.8,"impactScore":2.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16241","cwe":"CWE-191","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-16241","date":"2026-10-07","epss":0.00198,"percentile":0.08828}],"urls":["https://www.postgresql.org/support/security/CVE-2026-16241/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16241","description":"Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix.  The client overwrites a huge memory region with bytes outside attacker knowledge or control.  This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14673","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14673","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.8,"impactScore":2.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14673","cwe":"CWE-426","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14673","date":"2026-10-07","epss":0.00174,"percentile":0.06283}],"risk":0.05916,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14673","description":"Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function.  Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected.  PostgreSQL 17 is unaffected."},"relatedVulnerabilities":[{"id":"CVE-2026-14673","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.8,"impactScore":2.6,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14673","cwe":"CWE-426","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14673","date":"2026-10-07","epss":0.00174,"percentile":0.06283}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14673/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14673","description":"Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function.  Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected.  PostgreSQL 17 is unaffected."}]},{"artifact":{"id":"b6ee860d702b8084","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgssapi-krb5-2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgssapi-krb5-2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"52ef833c1503e21a","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libk5crypto3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libk5crypto3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"d4c94f2fc66f3184","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5-3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5-3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"56fc39be304d53f0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5support0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5support0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26461","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26461","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"risk":0.056400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26461","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26461","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-26461","date":"2026-10-07","epss":0.01128,"percentile":0.65316}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_2.md","https://security.netapp.com/advisory/ntap-20240415-0011/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26461","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c."}]},{"artifact":{"id":"5826072934743d2f","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.11.0-7:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/debian/libgcrypt20@1.11.0-7?arch=amd64&distro=debian-13.3","type":"deb","version":"1.11.0-7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgcrypt20","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgcrypt20","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2236","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"libgcrypt20","version":"1.11.0-7"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-2236","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-07","epss":0.01114,"percentile":0.64984}],"risk":0.055700000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."},"relatedVulnerabilities":[{"id":"CVE-2024-2236","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-07","epss":0.01114,"percentile":0.64984}],"urls":["https://access.redhat.com/errata/RHSA-2024:9404","https://access.redhat.com/errata/RHSA-2025:3530","https://access.redhat.com/errata/RHSA-2025:3534","https://access.redhat.com/security/cve/CVE-2024-2236","https://bugzilla.redhat.com/show_bug.cgi?id=2245218","https://bugzilla.redhat.com/show_bug.cgi?id=2268268"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14663","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14663","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14663","cwe":"CWE-313","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-14663","cwe":"CWE-345","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14663","date":"2026-10-07","epss":0.00096,"percentile":0.00654}],"risk":0.0552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14663","description":"Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext.  The OpenSSL version and OpenSSL configuration determine the disabled ciphers.  If the application accepts encrypted data as input, decryption will succeed even with the wrong key.  This in turn loses the modest protection from the Modification Detection Code (MDC).  Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."},"relatedVulnerabilities":[{"id":"CVE-2026-14663","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14663","cwe":"CWE-313","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"cve":"CVE-2026-14663","cwe":"CWE-345","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14663","date":"2026-10-07","epss":0.00096,"percentile":0.00654}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14663/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14663","description":"Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext.  The OpenSSL version and OpenSSL configuration determine the disabled ciphers.  If the application accepts encrypted data as input, decryption will succeed even with the wrong key.  This in turn loses the modest protection from the Modification Detection Code (MDC).  Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40226","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40226","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-07","epss":0.00094,"percentile":0.00563}],"risk":0.05358,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40226","description":"In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file."},"relatedVulnerabilities":[{"id":"CVE-2026-40226","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-07","epss":0.00094,"percentile":0.00563}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-9mj4-rrc3-gjcx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40226","description":"In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file."}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"257.13-1~deb13u1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40226","versionConstraint":"< 257.13-1~deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40226","fix":{"state":"fixed","versions":["257.13-1~deb13u1"],"available":[{"date":"2026-05-17","kind":"first-observed","version":"257.13-1~deb13u1"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-07","epss":0.00094,"percentile":0.00563}],"risk":0.05358,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40226","description":"In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file."},"relatedVulnerabilities":[{"id":"CVE-2026-40226","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-07","epss":0.00094,"percentile":0.00563}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-9mj4-rrc3-gjcx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40226","description":"In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file."}]},{"artifact":{"id":"3adf2ecac1ecb02e","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace:v1.44.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.44.0","type":"go-module","version":"v1.44.0","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace","version":"v1.44.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"84a867fedbe0aa09","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace\\/otlptracegrpc:v1.44.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.44.0","type":"go-module","version":"v1.44.0","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc","version":"v1.44.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"e3b51e9758f09472","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace\\/otlptracehttp:v1.44.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.44.0","type":"go-module","version":"v1.44.0","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp","version":"v1.44.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"af9d559bed3a6094","cpes":["cpe:2.3:a:otel:sdk:v1.44.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/sdk","purl":"pkg:golang/go.opentelemetry.io/otel/sdk@v1.44.0","type":"go-module","version":"v1.44.0","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/sdk","version":"v1.44.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-07","epss":0.00195,"percentile":0.08427}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-07","epss":0.00139,"percentile":0.02811}],"risk":0.04378499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-07","epss":0.00139,"percentile":0.02811}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-07","epss":0.00139,"percentile":0.02811}],"risk":0.04378499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-07","epss":0.00139,"percentile":0.02811}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-07","epss":0.00129,"percentile":0.02182}],"risk":0.04257,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.  When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-07","epss":0.00129,"percentile":0.02182}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"b6ee860d702b8084","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgssapi-krb5-2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgssapi-krb5-2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"52ef833c1503e21a","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libk5crypto3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libk5crypto3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"d4c94f2fc66f3184","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5-3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5-3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"56fc39be304d53f0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5support0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5support0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-26458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-26458","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"risk":0.04075,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."},"relatedVulnerabilities":[{"id":"CVE-2024-26458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-26458","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-26458","date":"2026-10-07","epss":0.00815,"percentile":0.55734}],"urls":["https://github.com/LuMingYinDetect/krb5_defects/blob/main/krb5_detect_1.md","https://security.netapp.com/advisory/ntap-20240415-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-26458","description":"Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c."}]},{"artifact":{"id":"86d39bad75a04a2d","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u1:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=glibc","type":"deb","version":"2.41-12+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status.d/libc6","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/status.d/libc6.md5sums","layerID":"sha256:63f271ba879a0f9e97d1ab2abfbc56436bfdcb86d1d6e21f22f9f28f9c76a01b","accessPath":"/var/lib/dpkg/status.d/libc6.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"glibc","version":"2.41-12+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-07","epss":0.00146,"percentile":0.03335}],"risk":0.03723,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-07","epss":0.00146,"percentile":0.03335}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-07","epss":0.00057,"percentile":0.00004}],"risk":0.03334499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-07","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-07","epss":0.00057,"percentile":0.00004}],"risk":0.03334499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-07","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"b007e005ccea828d","cpes":["cpe:2.3:a:libpq5:libpq5:17.8-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libpq5","purl":"pkg:deb/debian/libpq5@17.8-0%2Bdeb13u1?arch=amd64&distro=debian-13.3&upstream=postgresql-17","type":"deb","version":"17.8-0+deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libpq5","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libpq5","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"postgresql-17"}]},"matchDetails":[{"fix":{"suggestedVersion":"17.11-0+deb13u1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-14681","versionConstraint":"< 17.11-0+deb13u1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"postgresql-17","version":"17.8-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-14681","fix":{"state":"fixed","versions":["17.11-0+deb13u1"],"available":[{"date":"2026-08-13","kind":"advisory","version":"17.11-0+deb13u1"}]},"cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14681","cwe":"CWE-924","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14681","date":"2026-10-07","epss":0.00066,"percentile":0.00015}],"risk":0.03036,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6438-1","link":"https://security-tracker.debian.org/tracker/DSA-6438-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-14681","description":"Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection.  Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone.  If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection.  Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected.  Versions before PostgreSQL 17 are unaffected."},"relatedVulnerabilities":[{"id":"CVE-2026-14681","cvss":[{"type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14681","cwe":"CWE-924","type":"Secondary","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"}],"epss":[{"cve":"CVE-2026-14681","date":"2026-10-07","epss":0.00066,"percentile":0.00015}],"urls":["https://www.postgresql.org/support/security/CVE-2026-14681/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14681","description":"Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection.  Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone.  If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection.  Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected.  Versions before PostgreSQL 17 are unaffected."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-07","epss":0.0055,"percentile":0.44232}],"risk":0.0275,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-07","epss":0.0055,"percentile":0.44232}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9547","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9547","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-9547","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9547","date":"2026-10-07","epss":0.00508,"percentile":0.41369}],"risk":0.025400000000000006,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9547","description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack."},"relatedVulnerabilities":[{"id":"CVE-2026-9547","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9547","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9547","date":"2026-10-07","epss":0.00508,"percentile":0.41369}],"urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15224","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15224","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-07","epss":0.0048,"percentile":0.39414}],"risk":0.023999999999999997,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15224","description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent."},"relatedVulnerabilities":[{"id":"CVE-2025-15224","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-07","epss":0.0048,"percentile":0.39414}],"urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2013-4392","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-07","epss":0.00468,"percentile":0.38508}],"risk":0.0234,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."},"relatedVulnerabilities":[{"id":"CVE-2013-4392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"impactScore":5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-07","epss":0.00468,"percentile":0.38508}],"urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2013-4392","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2013-4392","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-07","epss":0.00468,"percentile":0.38508}],"risk":0.0234,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."},"relatedVulnerabilities":[{"id":"CVE-2013-4392","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":3.3,"impactScore":5,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2013-4392","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2013-4392","date":"2026-10-07","epss":0.00468,"percentile":0.38508}],"urls":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357","http://www.openwall.com/lists/oss-security/2013/10/01/9","https://bugzilla.redhat.com/show_bug.cgi?id=859060"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-4392","description":"systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82208","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82208","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82208","date":"2026-10-07","epss":0.00407,"percentile":0.32892}],"risk":0.02035,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82208","description":"With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after the callback returns. A certificate trusted by the cached store but rejected by the callback-selected store is then incorrectly accepted."},"relatedVulnerabilities":[{"id":"CVE-2026-82208","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82208","date":"2026-10-07","epss":0.00407,"percentile":0.32892}],"urls":["https://curl.se/docs/CVE-2026-82208.html","https://curl.se/docs/CVE-2026-82208.json","https://hackerone.com/reports/3973090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82208","description":"With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-10966","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-10966","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-10966","cwe":"CWE-322","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2025-10966","date":"2026-10-07","epss":0.00399,"percentile":0.31956}],"risk":0.01995,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-10966","description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.  This prevents curl from detecting MITM attackers and more."},"relatedVulnerabilities":[{"id":"CVE-2025-10966","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10966","cwe":"CWE-322","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2025-10966","date":"2026-10-07","epss":0.00399,"percentile":0.31956}],"urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-31439","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-07","epss":0.00349,"percentile":0.26421}],"risk":0.01745,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31439","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-07","epss":0.00349,"percentile":0.26421}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-31439","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-31439","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-07","epss":0.00349,"percentile":0.26421}],"risk":0.01745,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31439","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31439","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31439","date":"2026-10-07","epss":0.00349,"percentile":0.26421}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28885","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31439","description":"An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"46230cf5226e2e82","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.3&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libldap2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libldap2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-14159","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-14159","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-14159","date":"2026-10-07","epss":0.00346,"percentile":0.26053}],"risk":0.0173,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-14159","description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript."},"relatedVulnerabilities":[{"id":"CVE-2017-14159","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":1.9,"impactScore":2.9,"exploitabilityScore":3.4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-14159","cwe":"CWE-665","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-14159","date":"2026-10-07","epss":0.00346,"percentile":0.26053}],"urls":["http://www.openldap.org/its/index.cgi?findid=8703","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-14159","description":"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript."}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-31437","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-07","epss":0.00341,"percentile":0.25542}],"risk":0.01705,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-07","epss":0.00341,"percentile":0.25542}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-31437","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-31437","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-07","epss":0.00341,"percentile":0.25542}],"risk":0.01705,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31437","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-31437","cwe":"CWE-354","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-31437","date":"2026-10-07","epss":0.00341,"percentile":0.25542}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31437","description":"An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"4f3b916d8498c51d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.9-1~deb13u1?arch=amd64&distro=debian-13.3&upstream=systemd","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libsystemd0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libsystemd0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-31438","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-07","epss":0.00325,"percentile":0.23554}],"risk":0.01625,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31438","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-07","epss":0.00325,"percentile":0.23554}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"49db2eae5abce987","cpes":["cpe:2.3:a:systemd:systemd:257.9-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/Debian/systemd@257.9-1~deb13u1?distro=Debian","type":"deb","version":"257.9-1~deb13u1","language":"","licenses":[],"locations":[{"path":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/usr/lib/x86_64-linux-gnu/libsystemd.so.0.40.0","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-31438","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"systemd","version":"257.9-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2023-31438","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-07","epss":0.00325,"percentile":0.23554}],"risk":0.01625,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""},"relatedVulnerabilities":[{"id":"CVE-2023-31438","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-31438","cwe":"CWE-354","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-31438","date":"2026-10-07","epss":0.00325,"percentile":0.23554}],"urls":["https://github.com/kastel-security/Journald","https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf","https://github.com/systemd/systemd/pull/28886","https://github.com/systemd/systemd/releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-31438","description":"An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent \"a reply denying that any of the finding was a security vulnerability.\""}]},{"artifact":{"id":"b6ee860d702b8084","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libgssapi-krb5-2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libgssapi-krb5-2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"52ef833c1503e21a","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libk5crypto3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libk5crypto3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"d4c94f2fc66f3184","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5-3","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5-3","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"56fc39be304d53f0","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5?arch=amd64&distro=debian-13.3&upstream=krb5","type":"deb","version":"1.21.3-5","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libkrb5support0","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libkrb5support0","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11850","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"krb5","version":"1.21.3-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11850","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"risk":0.013550000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."},"relatedVulnerabilities":[{"id":"CVE-2026-11850","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11850","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-11850","date":"2026-10-07","epss":0.00271,"percentile":0.17697}],"urls":["https://access.redhat.com/errata/RHSA-2026:25520","https://access.redhat.com/security/cve/CVE-2026-11850","https://bugzilla.redhat.com/show_bug.cgi?id=2459970"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11850","description":"An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read.\nThe attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data."}]},{"artifact":{"id":"46230cf5226e2e82","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.3&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libldap2","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libldap2","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-22185","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-22185","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-22185","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-22185","date":"2026-10-07","epss":0.00152,"percentile":0.03784}],"risk":0.007600000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-22185","description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition."},"relatedVulnerabilities":[{"id":"CVE-2026-22185","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22185","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-22185","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-22185","date":"2026-10-07","epss":0.00152,"percentile":0.03784}],"urls":["https://bugs.openldap.org/show_bug.cgi?id=10421","https://seclists.org/fulldisclosure/2026/Jan/5","https://seclists.org/fulldisclosure/2026/Jan/8","https://www.openldap.org/","https://www.vulncheck.com/advisories/openldap-lmdb-mdb-load-heap-buffer-underflow-in-readline"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22185","description":"OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition."}]},{"artifact":{"id":"2c9e2faa683beba2","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u2:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?arch=amd64&distro=debian-13.3&upstream=curl","type":"deb","version":"8.14.1-2+deb13u2","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status.d/libcurl4t64","layerID":"sha256:26157e3a3b0e0cc592e2762c9b4a0f31f58621f1a2f4bf20d99d86d73bc187da","accessPath":"/var/lib/dpkg/status.d/libcurl4t64","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14017","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.3"},"package":{"name":"curl","version":"8.14.1-2+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-14017","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-14017","cwe":"CWE-567","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14017","date":"2026-10-07","epss":0.00114,"percentile":0.01364}],"risk":0.0057,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-14017","description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.  Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well."},"relatedVulnerabilities":[{"id":"CVE-2025-14017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14017","cwe":"CWE-567","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14017","date":"2026-10-07","epss":0.00114,"percentile":0.01364}],"urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well."}]},{"artifact":{"id":"fe94d0b23987bd10","cpes":["cpe:2.3:a:golang:crypto:v0.56.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.56.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.56.0","type":"go-module","version":"v0.56.0","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/loki/v3","architecture":"amd64","goCompiledVersion":"go1.26.5"},"locations":[{"path":"/fluent-bit/bin/out_grafana_loki.so","layerID":"sha256:404be7eca03bb886be6379a7a7e2888570bc64a3f4e5b29d9c078b8dfd155f28","accessPath":"/fluent-bit/bin/out_grafana_loki.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5932","versionConstraint":"none (unknown)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.56.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5932","fix":{"state":"","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/44226","description":"The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.\n\nIf you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package."},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-08T16:25:20.702Z","grype_db_version":"2026-10-08T06:33:47.000Z"}