{"grype_matches":[{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.0015,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45447"},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.0015,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45447"},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"fc79954134fe2e5a","cpes":["cpe:2.3:a:google:grpc:v1.67.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.67.1","type":"go-module","version":"v1.67.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:zWnc1Vrcno+lHZCOofnIMvycFcc0QRGIzm9dhnDX68E=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.79.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p77j-4mvh-x3m3","versionConstraint":"<1.79.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.67.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-p77j-4mvh-x3m3","fix":{"state":"fixed","versions":["1.79.3"],"available":[{"date":"2026-03-19","kind":"first-observed","version":"1.79.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33186","cwe":"CWE-285","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33186","cwe":"CWE-551","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33186","date":"2026-10-08","epss":0.01625,"percentile":0.75415}],"risk":1.470625,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3","https://nvd.nist.gov/vuln/detail/CVE-2026-33186"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p77j-4mvh-x3m3","description":"gRPC-Go has an authorization bypass via missing leading slash in :path"},"relatedVulnerabilities":[{"id":"CVE-2026-33186","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33186","cwe":"CWE-285","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33186","cwe":"CWE-551","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33186","date":"2026-10-08","epss":0.01625,"percentile":0.75415}],"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3","https://access.redhat.com/errata/RHSA-2026:10093","https://access.redhat.com/errata/RHSA-2026:10094","https://access.redhat.com/errata/RHSA-2026:10105","https://access.redhat.com/errata/RHSA-2026:10107","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10126","https://access.redhat.com/errata/RHSA-2026:10130","https://access.redhat.com/errata/RHSA-2026:10131","https://access.redhat.com/errata/RHSA-2026:10153","https://access.redhat.com/errata/RHSA-2026:10155","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10172","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10698","https://access.redhat.com/errata/RHSA-2026:10705","https://access.redhat.com/errata/RHSA-2026:10706","https://access.redhat.com/errata/RHSA-2026:11070","https://access.redhat.com/errata/RHSA-2026:11408","https://access.redhat.com/errata/RHSA-2026:11803","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12116","https://access.redhat.com/errata/RHSA-2026:12118","https://access.redhat.com/errata/RHSA-2026:12119","https://access.redhat.com/errata/RHSA-2026:12277","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:12283","https://access.redhat.com/errata/RHSA-2026:12337","https://access.redhat.com/errata/RHSA-2026:13548","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14775","https://access.redhat.com/errata/RHSA-2026:15092","https://access.redhat.com/errata/RHSA-2026:17123","https://access.redhat.com/errata/RHSA-2026:17448","https://access.redhat.com/errata/RHSA-2026:17459","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17474","https://access.redhat.com/errata/RHSA-2026:17475","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:17599","https://access.redhat.com/errata/RHSA-2026:17789","https://access.redhat.com/errata/RHSA-2026:18068","https://access.redhat.com/errata/RHSA-2026:18585","https://access.redhat.com/errata/RHSA-2026:19099","https://access.redhat.com/errata/RHSA-2026:19108","https://access.redhat.com/errata/RHSA-2026:19109","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:20034","https://access.redhat.com/errata/RHSA-2026:20035","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20042","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20089","https://access.redhat.com/errata/RHSA-2026:20322","https://access.redhat.com/errata/RHSA-2026:20436","https://access.redhat.com/errata/RHSA-2026:20943","https://access.redhat.com/errata/RHSA-2026:20946","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21658","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21692","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21697","https://access.redhat.com/errata/RHSA-2026:21703","https://access.redhat.com/errata/RHSA-2026:21704","https://access.redhat.com/errata/RHSA-2026:21709","https://access.redhat.com/errata/RHSA-2026:21710","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21931","https://access.redhat.com/errata/RHSA-2026:21932","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22645","https://access.redhat.com/errata/RHSA-2026:22689","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22800","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23234","https://access.redhat.com/errata/RHSA-2026:23235","https://access.redhat.com/errata/RHSA-2026:23241","https://access.redhat.com/errata/RHSA-2026:23246","https://access.redhat.com/errata/RHSA-2026:23247","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24484","https://access.redhat.com/errata/RHSA-2026:24506","https://access.redhat.com/errata/RHSA-2026:24535","https://access.redhat.com/errata/RHSA-2026:24536","https://access.redhat.com/errata/RHSA-2026:24759","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25009","https://access.redhat.com/errata/RHSA-2026:25045","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25182","https://access.redhat.com/errata/RHSA-2026:25183","https://access.redhat.com/errata/RHSA-2026:25187","https://access.redhat.com/errata/RHSA-2026:25194","https://access.redhat.com/errata/RHSA-2026:25195","https://access.redhat.com/errata/RHSA-2026:25201","https://access.redhat.com/errata/RHSA-2026:26412","https://access.redhat.com/errata/RHSA-2026:26413","https://access.redhat.com/errata/RHSA-2026:26416","https://access.redhat.com/errata/RHSA-2026:26420","https://access.redhat.com/errata/RHSA-2026:26519","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26997","https://access.redhat.com/errata/RHSA-2026:26999","https://access.redhat.com/errata/RHSA-2026:27001","https://access.redhat.com/errata/RHSA-2026:27004","https://access.redhat.com/errata/RHSA-2026:27063","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:27712","https://access.redhat.com/errata/RHSA-2026:27856","https://access.redhat.com/errata/RHSA-2026:27892","https://access.redhat.com/errata/RHSA-2026:27893","https://access.redhat.com/errata/RHSA-2026:27901","https://access.redhat.com/errata/RHSA-2026:27957","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28964","https://access.redhat.com/errata/RHSA-2026:29079","https://access.redhat.com/errata/RHSA-2026:29082","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:34049","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34099","https://access.redhat.com/errata/RHSA-2026:34100","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34769","https://access.redhat.com/errata/RHSA-2026:34794","https://access.redhat.com/errata/RHSA-2026:34795","https://access.redhat.com/errata/RHSA-2026:36611","https://access.redhat.com/errata/RHSA-2026:36621","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/errata/RHSA-2026:37192","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37580","https://access.redhat.com/errata/RHSA-2026:37585","https://access.redhat.com/errata/RHSA-2026:40022","https://access.redhat.com/errata/RHSA-2026:40030","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40792","https://access.redhat.com/errata/RHSA-2026:40795","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40984","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:41944","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43225","https://access.redhat.com/errata/RHSA-2026:43227","https://access.redhat.com/errata/RHSA-2026:43253","https://access.redhat.com/errata/RHSA-2026:43331","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44233","https://access.redhat.com/errata/RHSA-2026:44235","https://access.redhat.com/errata/RHSA-2026:47728","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48699","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:50758","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:53728","https://access.redhat.com/errata/RHSA-2026:53763","https://access.redhat.com/errata/RHSA-2026:53773","https://access.redhat.com/errata/RHSA-2026:53804","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56959","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60146","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:6174","https://access.redhat.com/errata/RHSA-2026:6428","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:7110","https://access.redhat.com/errata/RHSA-2026:7128","https://access.redhat.com/errata/RHSA-2026:7245","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8449","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9388","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-33186","https://bugzilla.redhat.com/show_bug.cgi?id=2449833","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33186.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33186","description":"gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, \"deny\" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback \"allow\" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific \"deny\" rules for canonical paths but allows other requests by default (a fallback \"allow\" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening."}]},{"artifact":{"id":"72d655d69efc5cbb","cpes":["cpe:2.3:a:apache:thrift:v0.21.0:*:*:*:*:*:*:*"],"name":"github.com/apache/thrift","purl":"pkg:golang/github.com/apache/thrift@v0.21.0","type":"go-module","version":"v0.21.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:tdPmh/ptjE1IJnhbhrcl2++TauVjy242rkV/UzJChnE=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.23.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wf45-q9ch-q8gh","versionConstraint":"<0.23.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/apache/thrift","version":"v0.21.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-wf45-q9ch-q8gh","fix":{"state":"fixed","versions":["0.23.0"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"0.23.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41602","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-41602","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41602","date":"2026-10-08","epss":0.0138,"percentile":0.71285}],"risk":1.035,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-41602","https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql","http://www.openwall.com/lists/oss-security/2026/04/28/6"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wf45-q9ch-q8gh","description":"Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2026-41602","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41602","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-41602","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41602","date":"2026-10-08","epss":0.0138,"percentile":0.71285}],"urls":["https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql","http://www.openwall.com/lists/oss-security/2026/04/28/6","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14885","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24503","https://access.redhat.com/errata/RHSA-2026:24539","https://access.redhat.com/errata/RHSA-2026:25273","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/security/cve/CVE-2026-41602","https://bugzilla.redhat.com/show_bug.cgi?id=2463407","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41602.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41602","description":"Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue."}]},{"artifact":{"id":"72d655d69efc5cbb","cpes":["cpe:2.3:a:apache:thrift:v0.21.0:*:*:*:*:*:*:*"],"name":"github.com/apache/thrift","purl":"pkg:golang/github.com/apache/thrift@v0.21.0","type":"go-module","version":"v0.21.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:tdPmh/ptjE1IJnhbhrcl2++TauVjy242rkV/UzJChnE=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.24.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wv5-x4w7-5gww","versionConstraint":"<0.24.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/apache/thrift","version":"v0.21.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wv5-x4w7-5gww","fix":{"state":"fixed","versions":["0.24.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0.24.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43871","cwe":"CWE-835","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-43871","date":"2026-10-08","epss":0.0103,"percentile":0.62624}],"risk":0.8034000000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-43871","https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9","https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby","http://www.openwall.com/lists/oss-security/2026/07/24/33"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wv5-x4w7-5gww","description":"Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop"},"relatedVulnerabilities":[{"id":"CVE-2026-43871","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@apache.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43871","cwe":"CWE-835","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-43871","date":"2026-10-08","epss":0.0103,"percentile":0.62624}],"urls":["https://lists.apache.org/thread/7v3jhgwfbmhx42424phydlnzb109g8b9","https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby","http://www.openwall.com/lists/oss-security/2026/07/24/33"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43871","description":"Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.\n\nUsers are recommended to upgrade to version 0.24.0, which fixes the issue."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":0.8009999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-63076"},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63076","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":0.8009999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-63076"},"relatedVulnerabilities":[{"id":"CVE-2026-63076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"c95b384f90bfaa01","cpes":["cpe:2.3:a:grafana:loki:v1.6.2-0.20240510183741-cef4c2826b4b:*:*:*:*:*:*:*"],"name":"github.com/grafana/loki","purl":"pkg:golang/github.com/grafana/loki@v1.6.2-0.20240510183741-cef4c2826b4b","type":"go-module","version":"v1.6.2-0.20240510183741-cef4c2826b4b","language":"go","licenses":[],"metadata":{"h1Digest":"h1:x5JsSnExxRl9kTMNqHebMCv0fn+V1+T16z7Tgz6xYf4=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.3.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-grj5-8x6q-hc9q","versionConstraint":"<2.3.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/grafana/loki","version":"v1.6.2-0.20240510183741-cef4c2826b4b"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-grj5-8x6q-hc9q","fix":{"state":"fixed","versions":["2.3.0"],"available":[{"date":"2022-03-03","kind":"first-observed","version":"2.3.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36156","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36156","date":"2026-10-08","epss":0.01477,"percentile":0.73079}],"risk":0.760655,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2021-36156","https://github.com/grafana/loki/pull/4020#issue-694377133","https://github.com/grafana/loki/releases/tag/v2.3.0","https://github.com/grafana/loki/pull/4020"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-grj5-8x6q-hc9q","description":"Path traversal in Grafana Loki"},"relatedVulnerabilities":[{"id":"CVE-2021-36156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-36156","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-36156","date":"2026-10-08","epss":0.01477,"percentile":0.73079}],"urls":["https://github.com/grafana/loki/pull/4020#issue-694377133","https://github.com/grafana/loki/releases/tag/v2.3.0"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-36156","description":"An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of the contents in the error message."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":0.7503,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28388"},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":0.7503,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28388"},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":0.7305,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28389"},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":0.7305,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28389"},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"fb5d7c7f68da22a3","cpes":["cpe:2.3:a:golang:x\\/oauth2:v0.26.0:*:*:*:*:*:*:*"],"name":"golang.org/x/oauth2","purl":"pkg:golang/golang.org/x/oauth2@v0.26.0","type":"go-module","version":"v0.26.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:afQXWNNaeC4nvZ0Ed9XvCCzXM6UHJG7iCg0W4fPqSBE=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.27.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6v2p-p543-phr9","versionConstraint":"<0.27.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/oauth2","version":"v0.26.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-6v2p-p543-phr9","fix":{"state":"fixed","versions":["0.27.0"],"available":[{"date":"2025-07-19","kind":"first-observed","version":"0.27.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22868","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22868","date":"2026-10-08","epss":0.0087,"percentile":0.57539}],"risk":0.6525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-22868","https://go.dev/cl/652155","https://go.dev/issue/71490","https://pkg.go.dev/vuln/GO-2025-3488"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6v2p-p543-phr9","description":"golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2025-22868","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22868","cwe":"CWE-1286","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22868","date":"2026-10-08","epss":0.0087,"percentile":0.57539}],"urls":["https://go.dev/cl/652155","https://go.dev/issue/71490","https://pkg.go.dev/vuln/GO-2025-3488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22868","description":"An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f5wc-c3c7-36mc","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-f5wc-c3c7-36mc","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39832","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39832","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39832","date":"2026-10-08","epss":0.00716,"percentile":0.52306}],"risk":0.64798,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39832","https://go.dev/cl/778642","https://go.dev/issue/79435","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5006","https://access.redhat.com/security/cve/CVE-2026-39832","https://bugzilla.redhat.com/show_bug.cgi?id=2480685","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f5wc-c3c7-36mc","description":"golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys"},"relatedVulnerabilities":[{"id":"CVE-2026-39832","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.7,"impactScore":5.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39832","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39832","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39832","date":"2026-10-08","epss":0.00716,"percentile":0.52306}],"urls":["https://go.dev/cl/778640","https://go.dev/cl/778641","https://go.dev/issue/79435","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5006","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39832","https://bugzilla.redhat.com/show_bug.cgi?id=2480685","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39832","description":"When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4601","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4601","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"risk":0.6255000000000001,"urls":["https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/752180","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-25679","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"urls":["https://go.dev/cl/752180","https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4601","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10133","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10169","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:10701","https://access.redhat.com/errata/RHSA-2026:10712","https://access.redhat.com/errata/RHSA-2026:10929","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11375","https://access.redhat.com/errata/RHSA-2026:11412","https://access.redhat.com/errata/RHSA-2026:11413","https://access.redhat.com/errata/RHSA-2026:11686","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:11800","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13642","https://access.redhat.com/errata/RHSA-2026:13643","https://access.redhat.com/errata/RHSA-2026:13671","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19022","https://access.redhat.com/errata/RHSA-2026:19026","https://access.redhat.com/errata/RHSA-2026:19027","https://access.redhat.com/errata/RHSA-2026:19031","https://access.redhat.com/errata/RHSA-2026:19032","https://access.redhat.com/errata/RHSA-2026:19049","https://access.redhat.com/errata/RHSA-2026:19055","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19128","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19181","https://access.redhat.com/errata/RHSA-2026:19184","https://access.redhat.com/errata/RHSA-2026:19185","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19475","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20581","https://access.redhat.com/errata/RHSA-2026:20582","https://access.redhat.com/errata/RHSA-2026:20584","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22733","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24386","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:25043","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26445","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52389","https://access.redhat.com/errata/RHSA-2026:52390","https://access.redhat.com/errata/RHSA-2026:52391","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:5941","https://access.redhat.com/errata/RHSA-2026:5942","https://access.redhat.com/errata/RHSA-2026:5943","https://access.redhat.com/errata/RHSA-2026:5944","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:6341","https://access.redhat.com/errata/RHSA-2026:6344","https://access.redhat.com/errata/RHSA-2026:6382","https://access.redhat.com/errata/RHSA-2026:6383","https://access.redhat.com/errata/RHSA-2026:6388","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:6720","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:6949","https://access.redhat.com/errata/RHSA-2026:7005","https://access.redhat.com/errata/RHSA-2026:7009","https://access.redhat.com/errata/RHSA-2026:7011","https://access.redhat.com/errata/RHSA-2026:7259","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7315","https://access.redhat.com/errata/RHSA-2026:7328","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7665","https://access.redhat.com/errata/RHSA-2026:7669","https://access.redhat.com/errata/RHSA-2026:7674","https://access.redhat.com/errata/RHSA-2026:7833","https://access.redhat.com/errata/RHSA-2026:7834","https://access.redhat.com/errata/RHSA-2026:7876","https://access.redhat.com/errata/RHSA-2026:7877","https://access.redhat.com/errata/RHSA-2026:7878","https://access.redhat.com/errata/RHSA-2026:7879","https://access.redhat.com/errata/RHSA-2026:7883","https://access.redhat.com/errata/RHSA-2026:7992","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8314","https://access.redhat.com/errata/RHSA-2026:8322","https://access.redhat.com/errata/RHSA-2026:8324","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8434","https://access.redhat.com/errata/RHSA-2026:8456","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:8840","https://access.redhat.com/errata/RHSA-2026:8841","https://access.redhat.com/errata/RHSA-2026:8842","https://access.redhat.com/errata/RHSA-2026:8845","https://access.redhat.com/errata/RHSA-2026:8847","https://access.redhat.com/errata/RHSA-2026:8848","https://access.redhat.com/errata/RHSA-2026:8849","https://access.redhat.com/errata/RHSA-2026:8851","https://access.redhat.com/errata/RHSA-2026:8852","https://access.redhat.com/errata/RHSA-2026:8853","https://access.redhat.com/errata/RHSA-2026:8855","https://access.redhat.com/errata/RHSA-2026:8856","https://access.redhat.com/errata/RHSA-2026:8860","https://access.redhat.com/errata/RHSA-2026:8877","https://access.redhat.com/errata/RHSA-2026:8878","https://access.redhat.com/errata/RHSA-2026:8879","https://access.redhat.com/errata/RHSA-2026:8881","https://access.redhat.com/errata/RHSA-2026:8882","https://access.redhat.com/errata/RHSA-2026:8930","https://access.redhat.com/errata/RHSA-2026:8931","https://access.redhat.com/errata/RHSA-2026:8949","https://access.redhat.com/errata/RHSA-2026:9043","https://access.redhat.com/errata/RHSA-2026:9044","https://access.redhat.com/errata/RHSA-2026:9052","https://access.redhat.com/errata/RHSA-2026:9090","https://access.redhat.com/errata/RHSA-2026:9093","https://access.redhat.com/errata/RHSA-2026:9094","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9434","https://access.redhat.com/errata/RHSA-2026:9435","https://access.redhat.com/errata/RHSA-2026:9436","https://access.redhat.com/errata/RHSA-2026:9439","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9461","https://access.redhat.com/errata/RHSA-2026:9695","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-25679","https://bugzilla.redhat.com/show_bug.cgi?id=2445356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25679","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."}]},{"artifact":{"id":"928e44e5e603a57e","cpes":["cpe:2.3:a:opencontainers:runc:v1.1.14:*:*:*:*:*:*:*"],"name":"github.com/opencontainers/runc","purl":"pkg:golang/github.com/opencontainers/runc@v1.1.14","type":"go-module","version":"v1.1.14","language":"go","licenses":[],"metadata":{"h1Digest":"h1:rgSuzbmgz5DUJjeSnw337TxDbRuqjs6iqQck/2weR6w=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9493-h29p-rfm2","versionConstraint":"<=1.2.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/opencontainers/runc","version":"v1.1.14"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-9493-h29p-rfm2","fix":{"state":"fixed","versions":["1.2.8"],"available":[{"date":"2025-11-06","kind":"first-observed","version":"1.2.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-31133","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-31133","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-31133","date":"2026-10-08","epss":0.00844,"percentile":0.56693}],"risk":0.62456,"urls":["https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2","https://github.com/opencontainers/runc/commit/1a30a8f3d921acbbb6a4bb7e99da2c05f8d48522","https://github.com/opencontainers/runc/commit/5d7b2424072449872d1cd0c937f2ca25f418eb66","https://github.com/opencontainers/runc/commit/8476df83b534a2522b878c0507b3491def48db9f","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://nvd.nist.gov/vuln/detail/CVE-2025-31133"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9493-h29p-rfm2","description":"runc container escape via \"masked path\" abuse due to mount race conditions"},"relatedVulnerabilities":[{"id":"CVE-2025-31133","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":6.1,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-31133","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-31133","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-31133","date":"2026-10-08","epss":0.00844,"percentile":0.56693}],"urls":["https://github.com/opencontainers/runc/commit/1a30a8f3d921acbbb6a4bb7e99da2c05f8d48522","https://github.com/opencontainers/runc/commit/5d7b2424072449872d1cd0c937f2ca25f418eb66","https://github.com/opencontainers/runc/commit/8476df83b534a2522b878c0507b3491def48db9f","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-31133","description":"runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container's /dev/null) was actually a real /dev/null inode when using the container's /dev/null to mask. This exposes two methods of attack:  an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4981","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4981","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"risk":0.60975,"urls":["https://go.dev/cl/767860","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78803","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-33811","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"urls":["https://go.dev/cl/767860","https://go.dev/issue/78803","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4981","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:35995","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36617","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36776","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:39266","https://access.redhat.com/errata/RHSA-2026:39272","https://access.redhat.com/errata/RHSA-2026:39319","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54556","https://access.redhat.com/errata/RHSA-2026:54584","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56790","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60302","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61313","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/security/cve/CVE-2026-33811","https://bugzilla.redhat.com/show_bug.cgi?id=2467822","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4977","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4977","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"risk":0.5984999999999999,"urls":["https://go.dev/cl/771520","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78987","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."},"relatedVulnerabilities":[{"id":"CVE-2026-42499","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"urls":["https://go.dev/cl/771520","https://go.dev/issue/78987","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4977","https://access.redhat.com/errata/RHSA-2026:17713","https://access.redhat.com/errata/RHSA-2026:17714","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:63163","https://access.redhat.com/errata/RHSA-2026:63332","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:64818","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67148","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-42499","https://bugzilla.redhat.com/show_bug.cgi?id=2467809","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42499","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5cgq-3rg8-m6cv","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-5cgq-3rg8-m6cv","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42508","date":"2026-10-08","epss":0.00654,"percentile":0.49763}],"risk":0.59187,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-42508","https://go.dev/cl/781220","https://go.dev/issue/79568","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5021","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/security/cve/CVE-2026-42508","https://bugzilla.redhat.com/show_bug.cgi?id=2480688","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40138","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41064","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40945"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5cgq-3rg8-m6cv","description":"golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status"},"relatedVulnerabilities":[{"id":"CVE-2026-42508","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42508","date":"2026-10-08","epss":0.00654,"percentile":0.49763}],"urls":["https://go.dev/cl/781220","https://go.dev/issue/79568","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5021","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41064","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-42508","https://bugzilla.redhat.com/show_bug.cgi?id=2480688","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42508","description":"Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4986","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4986","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"risk":0.588,"urls":["https://go.dev/cl/759940","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78566","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-39820","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"urls":["https://go.dev/cl/759940","https://go.dev/issue/78566","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4986","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54883","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57401","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-39820","https://bugzilla.redhat.com/show_bug.cgi?id=2467820","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.53.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<0.53.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["0.53.0"],"available":[{"date":"2026-04-09","kind":"release","version":"0.53.0"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rm3j-f69w-wqmq","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-rm3j-f69w-wqmq","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39834","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39834","date":"2026-10-08","epss":0.00637,"percentile":0.48909}],"risk":0.576485,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39834","https://go.dev/cl/781663","https://go.dev/issue/79567","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5020"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rm3j-f69w-wqmq","description":"golang.org/x/crypto vulnerable to infinite loop on large channel writes"},"relatedVulnerabilities":[{"id":"CVE-2026-39834","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39834","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39834","date":"2026-10-08","epss":0.00637,"percentile":0.48909}],"urls":["https://go.dev/cl/781663","https://go.dev/issue/79567","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5020"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39834","description":"When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation."}]},{"artifact":{"id":"5017d6ff70706229","cpes":["cpe:2.3:a:etcd:client\\/pkg\\/v3:v3.5.10:*:*:*:*:*:*:*"],"name":"go.etcd.io/etcd/client/pkg/v3","purl":"pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.5.10","type":"go-module","version":"v3.5.10","language":"go","licenses":[],"metadata":{"h1Digest":"h1:kfYIdQftBnbAq8pUWFXfpuuxFSKzlmM5cSn76JByiT0=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.5.33"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6107","versionConstraint":"<3.5.33||>=3.6.0,<3.6.14||>=3.7.0-alpha.0,<3.7.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.etcd.io/etcd/client/pkg/v3","version":"v3.5.10"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6107","fix":{"state":"fixed","versions":["3.5.33","3.6.14","3.7.1"],"available":[{"date":"2026-07-23","kind":"release","version":"3.5.33"},{"date":"2026-07-23","kind":"release","version":"3.6.14"},{"date":"2026-07-23","kind":"release","version":"3.7.1"}]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73500","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73500","date":"2026-10-08","epss":0.00697,"percentile":0.51564}],"risk":0.5645699999999999,"urls":["https://github.com/etcd-io/etcd/pull/22130","https://github.com/etcd-io/etcd/releases/tag/v3.5.33","https://github.com/etcd-io/etcd/releases/tag/v3.6.14","https://github.com/etcd-io/etcd/releases/tag/v3.7.1"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3","description":"In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-73500","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73500","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73500","date":"2026-10-08","epss":0.00697,"percentile":0.51564}],"urls":["https://github.com/etcd-io/etcd/commit/2e07efce9745004eb4773cffaada9b5cdf77cff2","https://github.com/etcd-io/etcd/commit/89ff6d50796049d4f1136915ba21504b76e7e372","https://github.com/etcd-io/etcd/commit/8e4dd0679a2c6b095d2a32a749fda2521c7809a3","https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057","https://github.com/etcd-io/etcd/pull/22130","https://github.com/etcd-io/etcd/releases/tag/v3.5.33","https://github.com/etcd-io/etcd/releases/tag/v3.6.14","https://github.com/etcd-io/etcd/releases/tag/v3.7.1","https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73500","description":"etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls.Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1."},{"id":"GHSA-6vch-q96h-7gc3","cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73500","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73500","date":"2026-10-08","epss":0.00697,"percentile":0.51564}],"urls":["https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3","https://github.com/etcd-io/etcd/pull/22130","https://github.com/etcd-io/etcd/commit/2e07efce9745004eb4773cffaada9b5cdf77cff2","https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057","https://github.com/etcd-io/etcd/releases/tag/v3.5.33","https://github.com/etcd-io/etcd/releases/tag/v3.6.14","https://github.com/etcd-io/etcd/releases/tag/v3.7.1"],"severity":"High","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-6vch-q96h-7gc3","description":"etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline"}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42009","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42009","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42009","date":"2026-10-08","epss":0.01129,"percentile":0.65367}],"risk":0.5645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42009"},"relatedVulnerabilities":[{"id":"CVE-2026-42009","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42009","date":"2026-10-08","epss":0.01129,"percentile":0.65367}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:29794","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42009","https://bugzilla.redhat.com/show_bug.cgi?id=2467279","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42009","description":"A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vgwf-h737-ff37","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-vgwf-h737-ff37","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39830","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39830","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39830","date":"2026-10-08","epss":0.00621,"percentile":0.48178}],"risk":0.5620050000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39830","https://go.dev/cl/781640","https://go.dev/cl/781664","https://go.dev/issue/79564","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5017","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/security/cve/CVE-2026-39830","https://bugzilla.redhat.com/show_bug.cgi?id=2480684","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vgwf-h737-ff37","description":"golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses"},"relatedVulnerabilities":[{"id":"CVE-2026-39830","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39830","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39830","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39830","date":"2026-10-08","epss":0.00621,"percentile":0.48178}],"urls":["https://go.dev/cl/781640","https://go.dev/cl/781664","https://go.dev/issue/79564","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5017","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39830","https://bugzilla.redhat.com/show_bug.cgi?id=2480684","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39830","description":"A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33846","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33846","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33846","date":"2026-10-08","epss":0.01123,"percentile":0.65216}],"risk":0.5615,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33846"},"relatedVulnerabilities":[{"id":"CVE-2026-33846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33846","date":"2026-10-08","epss":0.01123,"percentile":0.65216}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33846","https://bugzilla.redhat.com/show_bug.cgi?id=2450625","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33846","description":"A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34182","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-34182","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405}],"risk":0.5285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-34182"},"relatedVulnerabilities":[{"id":"CVE-2026-34182","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405}],"urls":["https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc","https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f","https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7","https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac","https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34182","description":"Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-34182","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-34182","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405}],"risk":0.5285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-34182"},"relatedVulnerabilities":[{"id":"CVE-2026-34182","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405}],"urls":["https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc","https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f","https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7","https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac","https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34182","description":"Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"fc79954134fe2e5a","cpes":["cpe:2.3:a:google:grpc:v1.67.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.67.1","type":"go-module","version":"v1.67.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:zWnc1Vrcno+lHZCOofnIMvycFcc0QRGIzm9dhnDX68E=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.82.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2v4p-qf9q-27wj","versionConstraint":"<1.82.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.67.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-2v4p-qf9q-27wj","fix":{"state":"fixed","versions":["1.82.2"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"1.82.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84445","cwe":"CWE-129","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84445","cwe":"CWE-248","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84445","date":"2026-10-08","epss":0.00641,"percentile":0.49117}],"risk":0.51921,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj","https://github.com/grpc/grpc-go/issues/9354","https://github.com/grpc/grpc-go/pull/9365","https://github.com/grpc/grpc-go/pull/9366","https://github.com/grpc/grpc-go/pull/9367","https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7","https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4","https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f","https://github.com/grpc/grpc-go/releases/tag/v1.82.2","https://github.com/grpc/grpc-go/releases/tag/v1.83.2","https://nvd.nist.gov/vuln/detail/CVE-2026-84445"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2v4p-qf9q-27wj","description":"gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers"},"relatedVulnerabilities":[{"id":"CVE-2026-84445","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84445","cwe":"CWE-129","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84445","cwe":"CWE-248","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84445","date":"2026-10-08","epss":0.00641,"percentile":0.49117}],"urls":["https://github.com/grpc/grpc-go/commit/3822494d8ea03b992c089fd2a195f041762fffb7","https://github.com/grpc/grpc-go/commit/8668b69c167df908b6b3666dcbf40992b9e932a4","https://github.com/grpc/grpc-go/commit/93e31b48545e2a8aaeb6e06b47fb249f94e6297f","https://github.com/grpc/grpc-go/issues/9354","https://github.com/grpc/grpc-go/pull/9365","https://github.com/grpc/grpc-go/pull/9366","https://github.com/grpc/grpc-go/pull/9367","https://github.com/grpc/grpc-go/releases/tag/v1.82.2","https://github.com/grpc/grpc-go/releases/tag/v1.83.2","https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84445","description":"gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-31790","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-31790","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-31790","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31790","date":"2026-10-08","epss":0.0103,"percentile":0.62639}],"risk":0.515,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-31790"},"relatedVulnerabilities":[{"id":"CVE-2026-31790","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31790","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31790","date":"2026-10-08","epss":0.0103,"percentile":0.62639}],"urls":["https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac","https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482","https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406","https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790","https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31790","description":"Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-31790","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-31790","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-31790","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31790","date":"2026-10-08","epss":0.0103,"percentile":0.62639}],"risk":0.515,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-31790"},"relatedVulnerabilities":[{"id":"CVE-2026-31790","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31790","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31790","date":"2026-10-08","epss":0.0103,"percentile":0.62639}],"urls":["https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac","https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482","https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406","https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790","https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31790","description":"Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"fc79954134fe2e5a","cpes":["cpe:2.3:a:google:grpc:v1.67.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.67.1","type":"go-module","version":"v1.67.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:zWnc1Vrcno+lHZCOofnIMvycFcc0QRGIzm9dhnDX68E=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.83.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vp52-pcj8-j9qc","versionConstraint":"<=1.83.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.67.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-vp52-pcj8-j9qc","fix":{"state":"fixed","versions":["1.83.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"1.83.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84304","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84304","date":"2026-10-08","epss":0.00609,"percentile":0.47509}],"risk":0.49328999999999995,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc","https://nvd.nist.gov/vuln/detail/CVE-2026-84304","https://github.com/grpc/grpc-go/pull/9331","https://github.com/grpc/grpc-go/pull/9333","https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176","https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77","https://github.com/grpc/grpc-go/releases/tag/v1.83.1"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vp52-pcj8-j9qc","description":"gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation"},"relatedVulnerabilities":[{"id":"CVE-2026-84304","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84304","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84304","date":"2026-10-08","epss":0.00609,"percentile":0.47509}],"urls":["https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176","https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77","https://github.com/grpc/grpc-go/pull/9331","https://github.com/grpc/grpc-go/pull/9333","https://github.com/grpc/grpc-go/releases/tag/v1.83.1","https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84304","description":"gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1."}]},{"artifact":{"id":"311bb5ca01b47fc1","cpes":["cpe:2.3:a:go-jose:go-jose\\/v3:v3.0.4:*:*:*:*:*:*:*","cpe:2.3:a:go-jose:go_jose\\/v3:v3.0.4:*:*:*:*:*:*:*","cpe:2.3:a:go_jose:go-jose\\/v3:v3.0.4:*:*:*:*:*:*:*","cpe:2.3:a:go_jose:go_jose\\/v3:v3.0.4:*:*:*:*:*:*:*","cpe:2.3:a:go:go-jose\\/v3:v3.0.4:*:*:*:*:*:*:*","cpe:2.3:a:go:go_jose\\/v3:v3.0.4:*:*:*:*:*:*:*"],"name":"github.com/go-jose/go-jose/v3","purl":"pkg:golang/github.com/go-jose/go-jose/v3@v3.0.4","type":"go-module","version":"v3.0.4","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Wp5HA7bLQcKnf6YYao/4kpRpVMp/yf6+pJKV8WFSaNY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.0.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-78h2-9frx-2jm8","versionConstraint":"<3.0.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-jose/go-jose/v3","version":"v3.0.4"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-78h2-9frx-2jm8","fix":{"state":"fixed","versions":["3.0.5"],"available":[{"date":"2026-04-03","kind":"first-observed","version":"3.0.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34986","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34986","cwe":"CWE-131","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34986","date":"2026-10-08","epss":0.00651,"percentile":0.49627}],"risk":0.48824999999999996,"urls":["https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8","https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants","https://nvd.nist.gov/vuln/detail/CVE-2026-34986"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-78h2-9frx-2jm8","description":"Go JOSE Panics in JWE decryption"},"relatedVulnerabilities":[{"id":"CVE-2026-34986","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34986","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34986","cwe":"CWE-131","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-34986","date":"2026-10-08","epss":0.00651,"percentile":0.49627}],"urls":["https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8","https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10130","https://access.redhat.com/errata/RHSA-2026:10135","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:11070","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11512","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12116","https://access.redhat.com/errata/RHSA-2026:12277","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17121","https://access.redhat.com/errata/RHSA-2026:17123","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17448","https://access.redhat.com/errata/RHSA-2026:17458","https://access.redhat.com/errata/RHSA-2026:17459","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17474","https://access.redhat.com/errata/RHSA-2026:17547","https://access.redhat.com/errata/RHSA-2026:17550","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:17789","https://access.redhat.com/errata/RHSA-2026:18584","https://access.redhat.com/errata/RHSA-2026:18585","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19099","https://access.redhat.com/errata/RHSA-2026:19108","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19173","https://access.redhat.com/errata/RHSA-2026:19186","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:20034","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20946","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21703","https://access.redhat.com/errata/RHSA-2026:21709","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21931","https://access.redhat.com/errata/RHSA-2026:21932","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22629","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23241","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24471","https://access.redhat.com/errata/RHSA-2026:24475","https://access.redhat.com/errata/RHSA-2026:24477","https://access.redhat.com/errata/RHSA-2026:24479","https://access.redhat.com/errata/RHSA-2026:24482","https://access.redhat.com/errata/RHSA-2026:24484","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25187","https://access.redhat.com/errata/RHSA-2026:25194","https://access.redhat.com/errata/RHSA-2026:25206","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26054","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27001","https://access.redhat.com/errata/RHSA-2026:27004","https://access.redhat.com/errata/RHSA-2026:27044","https://access.redhat.com/errata/RHSA-2026:27063","https://access.redhat.com/errata/RHSA-2026:27856","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:32991","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34099","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34794","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40984","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:41944","https://access.redhat.com/errata/RHSA-2026:44267","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48085","https://access.redhat.com/errata/RHSA-2026:48676","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:56968","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57590","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60444","https://access.redhat.com/errata/RHSA-2026:60449","https://access.redhat.com/errata/RHSA-2026:60452","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62548","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65906","https://access.redhat.com/errata/RHSA-2026:66385","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9388","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/security/cve/CVE-2026-34986","https://bugzilla.redhat.com/show_bug.cgi?id=2455470","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34986.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34986","description":"Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5."}]},{"artifact":{"id":"2cfe9a71f87c96fe","cpes":["cpe:2.3:a:jackc:pgproto3\\/v2:v2.3.3:*:*:*:*:*:*:*"],"name":"github.com/jackc/pgproto3/v2","purl":"pkg:golang/github.com/jackc/pgproto3/v2@v2.3.3","type":"go-module","version":"v2.3.3","language":"go","licenses":[],"metadata":{"h1Digest":"h1:1HLSx5H+tXR9pW3in3zaztoEwQYRC9SQaYUHjTSUOag=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jqcq-xjh3-6g23","versionConstraint":">=2.0.0,<=2.3.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/jackc/pgproto3/v2","version":"v2.3.3"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-jqcq-xjh3-6g23","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32286","cwe":"CWE-129","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32286","cwe":"CWE-1285","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32286","date":"2026-10-08","epss":0.0065,"percentile":0.49587}],"risk":0.4875,"urls":["https://github.com/golang/vulndb/issues/4518","https://github.com/jackc/pgx/issues/2507","https://securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postgresql-wire-protocol-parsers-pgproto3-pgx","https://nvd.nist.gov/vuln/detail/CVE-2026-32286","https://pkg.go.dev/vuln/GO-2026-4518","https://bugzilla.redhat.com/show_bug.cgi?id=2448626"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jqcq-xjh3-6g23","description":"Denial of service in github.com/jackc/pgproto3/v2"},"relatedVulnerabilities":[{"id":"CVE-2026-32286","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32286","cwe":"CWE-129","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32286","cwe":"CWE-1285","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32286","date":"2026-10-08","epss":0.0065,"percentile":0.49587}],"urls":["https://github.com/advisories/GHSA-jqcq-xjh3-6g23","https://github.com/golang/vulndb/issues/4518","https://github.com/jackc/pgx/issues/2507","https://pkg.go.dev/vuln/GO-2026-4518","https://access.redhat.com/errata/RHSA-2026:11070","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/security/cve/CVE-2026-32286","https://bugzilla.redhat.com/show_bug.cgi?id=2451847","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32286.json","https://securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postgresql-wire-protocol-parsers-pgproto3-pgx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32286","description":"The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x527-x647-q7gg","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-x527-x647-q7gg","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"impactScore":6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46595","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-46595","cwe":"CWE-303","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46595","date":"2026-10-08","epss":0.00503,"percentile":0.41132}],"risk":0.47785,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-45337","https://nvd.nist.gov/vuln/detail/CVE-2026-46595","https://go.dev/cl/781642","https://go.dev/issue/79570","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5023","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/security/cve/CVE-2026-46595","https://bugzilla.redhat.com/show_bug.cgi?id=2480689","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40945"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x527-x647-q7gg","description":"golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement"},"relatedVulnerabilities":[{"id":"CVE-2026-46595","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"impactScore":6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46595","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-46595","cwe":"CWE-303","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46595","date":"2026-10-08","epss":0.00503,"percentile":0.41132}],"urls":["https://go.dev/cl/781642","https://go.dev/issue/79570","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5023","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-46595","https://bugzilla.redhat.com/show_bug.cgi?id=2480689","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46595","description":"Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5942","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5942","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-06-09","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"risk":0.47250000000000003,"urls":["https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/786345","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-46600","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46600","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46600","date":"2026-10-08","epss":0.0063,"percentile":0.48566}],"urls":["https://go.dev/cl/786345","https://go.dev/issue/79795","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5942"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46600","description":"Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5260","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5260","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5260","date":"2026-10-08","epss":0.00945,"percentile":0.59888}],"risk":0.47250000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5260"},"relatedVulnerabilities":[{"id":"CVE-2026-5260","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5260","date":"2026-10-08","epss":0.00945,"percentile":0.59888}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:67837","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5260","https://bugzilla.redhat.com/show_bug.cgi?id=2467450","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5260","description":"A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42010","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42010","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42010","date":"2026-10-08","epss":0.00944,"percentile":0.59864}],"risk":0.47200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42010"},"relatedVulnerabilities":[{"id":"CVE-2026-42010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42010","date":"2026-10-08","epss":0.00944,"percentile":0.59864}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:34790","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42010","https://bugzilla.redhat.com/show_bug.cgi?id=2467289","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42010","description":"A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w879-237q-wc7r","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w879-237q-wc7r","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39829","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39829","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39829","date":"2026-10-08","epss":0.00623,"percentile":0.48242}],"risk":0.46725000000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39829","https://go.dev/cl/781641","https://go.dev/cl/781661","https://go.dev/issue/79565","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5018","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/security/cve/CVE-2026-39829","https://bugzilla.redhat.com/show_bug.cgi?id=2480681","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40119","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41055"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w879-237q-wc7r","description":"golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-39829","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39829","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39829","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39829","date":"2026-10-08","epss":0.00623,"percentile":0.48242}],"urls":["https://go.dev/cl/781641","https://go.dev/cl/781661","https://go.dev/issue/79565","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5018","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48693","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39829","https://bugzilla.redhat.com/show_bug.cgi?id=2480681","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39829","description":"The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4870","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4870","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"risk":0.46575,"urls":["https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763767","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.\n\nThis only affects TLS 1.3."},"relatedVulnerabilities":[{"id":"CVE-2026-32283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"urls":["https://go.dev/cl/763767","https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4870","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11704","https://access.redhat.com/errata/RHSA-2026:11711","https://access.redhat.com/errata/RHSA-2026:11712","https://access.redhat.com/errata/RHSA-2026:11863","https://access.redhat.com/errata/RHSA-2026:11881","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17075","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19134","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19136","https://access.redhat.com/errata/RHSA-2026:19137","https://access.redhat.com/errata/RHSA-2026:19139","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19156","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19351","https://access.redhat.com/errata/RHSA-2026:19352","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19369","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55898","https://access.redhat.com/errata/RHSA-2026:55900","https://access.redhat.com/errata/RHSA-2026:55901","https://access.redhat.com/errata/RHSA-2026:55902","https://access.redhat.com/errata/RHSA-2026:55903","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:57802","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65343","https://access.redhat.com/errata/RHSA-2026:65514","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66084","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:66523","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/security/cve/CVE-2026-32283","https://bugzilla.redhat.com/show_bug.cgi?id=2456338","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32283","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4971","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4971","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"risk":0.46499999999999997,"urls":["https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://go.dev/cl/775320"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79006","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."},"relatedVulnerabilities":[{"id":"CVE-2026-39836","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"urls":["https://go.dev/cl/775320","https://go.dev/issue/79006","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4971"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4h4-gmj2-qvw2","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-q4h4-gmj2-qvw2","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46597","cwe":"CWE-704","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-46597","date":"2026-10-08","epss":0.0062,"percentile":0.48082}],"risk":0.46499999999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-46597","https://go.dev/cl/781620","https://go.dev/issue/79561","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5013"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4h4-gmj2-qvw2","description":"golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic"},"relatedVulnerabilities":[{"id":"CVE-2026-46597","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46597","cwe":"CWE-704","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-46597","date":"2026-10-08","epss":0.0062,"percentile":0.48082}],"urls":["https://go.dev/cl/781620","https://go.dev/issue/79561","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5013"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46597","description":"An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4947","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4947","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"risk":0.46125000000000005,"urls":["https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758320","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},"relatedVulnerabilities":[{"id":"CVE-2026-32280","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"urls":["https://go.dev/cl/758320","https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4947","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16476","https://access.redhat.com/errata/RHSA-2026:16477","https://access.redhat.com/errata/RHSA-2026:16505","https://access.redhat.com/errata/RHSA-2026:16508","https://access.redhat.com/errata/RHSA-2026:16532","https://access.redhat.com/errata/RHSA-2026:16534","https://access.redhat.com/errata/RHSA-2026:16535","https://access.redhat.com/errata/RHSA-2026:16537","https://access.redhat.com/errata/RHSA-2026:16542","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21338","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:22130","https://access.redhat.com/errata/RHSA-2026:22141","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22268","https://access.redhat.com/errata/RHSA-2026:22309","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22415","https://access.redhat.com/errata/RHSA-2026:22422","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22958","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22960","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:22962","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23244","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24359","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24478","https://access.redhat.com/errata/RHSA-2026:24716","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:28196","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:39894","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49526","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49838","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:59834","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61685","https://access.redhat.com/errata/RHSA-2026:61906","https://access.redhat.com/errata/RHSA-2026:61907","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/security/cve/CVE-2026-32280","https://bugzilla.redhat.com/show_bug.cgi?id=2456339","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32280","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42015","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42015","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42015","date":"2026-10-08","epss":0.0092,"percentile":0.59061}],"risk":0.45999999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42015"},"relatedVulnerabilities":[{"id":"CVE-2026-42015","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42015","date":"2026-10-08","epss":0.0092,"percentile":0.59061}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42015","https://bugzilla.redhat.com/show_bug.cgi?id=2467678","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42015","description":"A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.45799999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-63072"},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.45799999999999996,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-63072"},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3833","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3833","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3833","date":"2026-10-08","epss":0.00892,"percentile":0.58203}],"risk":0.44600000000000006,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3833"},"relatedVulnerabilities":[{"id":"CVE-2026-3833","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3833","date":"2026-10-08","epss":0.00892,"percentile":0.58203}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-3833","https://bugzilla.redhat.com/show_bug.cgi?id=2445763","https://gitlab.com/gnutls/gnutls/-/issues/1803"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3833","description":"A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-33845","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-33845","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-08","epss":0.00886,"percentile":0.58022}],"risk":0.443,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-33845"},"relatedVulnerabilities":[{"id":"CVE-2026-33845","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-08","epss":0.00886,"percentile":0.58022}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33845","https://bugzilla.redhat.com/show_bug.cgi?id=2450624","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33845","description":"A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-89gr-r52h-f8rx","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-89gr-r52h-f8rx","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39831","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39831","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"risk":0.440735,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39831","https://go.dev/cl/781662","https://go.dev/issue/79566","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5019"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-89gr-r52h-f8rx","description":"golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed"},"relatedVulnerabilities":[{"id":"CVE-2026-39831","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39831","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39831","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"urls":["https://go.dev/cl/781662","https://go.dev/issue/79566","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5019"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39831","description":"The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a \"no-touch-required\" extension in Permissions.Extensions from PublicKeyCallback."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jppx-rxg9-jmrx","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-jppx-rxg9-jmrx","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39833","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39833","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"risk":0.440735,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39833","https://go.dev/cl/778640","https://go.dev/cl/778641","https://go.dev/issue/79436","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5005"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jppx-rxg9-jmrx","description":"golang.org/x/crypto doesn't enforce invoking key constraints"},"relatedVulnerabilities":[{"id":"CVE-2026-39833","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39833","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39833","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"urls":["https://go.dev/cl/778642","https://go.dev/issue/79436","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5005"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39833","description":"The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3832","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3832","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3832","date":"2026-10-08","epss":0.0085,"percentile":0.56912}],"risk":0.42500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3832"},"relatedVulnerabilities":[{"id":"CVE-2026-3832","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3832","date":"2026-10-08","epss":0.0085,"percentile":0.56912}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-3832","https://bugzilla.redhat.com/show_bug.cgi?id=2445762","https://gitlab.com/gnutls/gnutls/-/issues/1801"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3832","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"928e44e5e603a57e","cpes":["cpe:2.3:a:opencontainers:runc:v1.1.14:*:*:*:*:*:*:*"],"name":"github.com/opencontainers/runc","purl":"pkg:golang/github.com/opencontainers/runc@v1.1.14","type":"go-module","version":"v1.1.14","language":"go","licenses":[],"metadata":{"h1Digest":"h1:rgSuzbmgz5DUJjeSnw337TxDbRuqjs6iqQck/2weR6w=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qw9x-cqr3-wc7r","versionConstraint":">=1.0.0-rc3,<=1.2.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/opencontainers/runc","version":"v1.1.14"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qw9x-cqr3-wc7r","fix":{"state":"fixed","versions":["1.2.8"],"available":[{"date":"2025-11-06","kind":"first-observed","version":"1.2.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52565","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-52565","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-52565","date":"2026-10-08","epss":0.00567,"percentile":0.45267}],"risk":0.41957999999999995,"urls":["https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r","https://github.com/opencontainers/runc/commit/01de9d65dc72f67b256ef03f9bfb795a2bf143b4","https://github.com/opencontainers/runc/commit/398955bccb7f20565c224a3064d331c19e422398","https://github.com/opencontainers/runc/commit/531ef794e4ecd628006a865ad334a048ee2b4b2e","https://github.com/opencontainers/runc/commit/9be1dbf4ac67d9840a043ebd2df5c68f36705d1d","https://github.com/opencontainers/runc/commit/aee7d3fe355dd02939d44155e308ea0052e0d53a","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://github.com/opencontainers/runc/commit/de87203e625cd7a27141fb5f2ad00a320c69c5e8","https://github.com/opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480","https://nvd.nist.gov/vuln/detail/CVE-2025-52565"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qw9x-cqr3-wc7r","description":"runc container escape with malicious config due to /dev/console mount and related races"},"relatedVulnerabilities":[{"id":"CVE-2025-52565","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52565","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-52565","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-52565","date":"2026-10-08","epss":0.00567,"percentile":0.45267}],"urls":["https://github.com/opencontainers/runc/commit/01de9d65dc72f67b256ef03f9bfb795a2bf143b4","https://github.com/opencontainers/runc/commit/398955bccb7f20565c224a3064d331c19e422398","https://github.com/opencontainers/runc/commit/531ef794e4ecd628006a865ad334a048ee2b4b2e","https://github.com/opencontainers/runc/commit/9be1dbf4ac67d9840a043ebd2df5c68f36705d1d","https://github.com/opencontainers/runc/commit/aee7d3fe355dd02939d44155e308ea0052e0d53a","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://github.com/opencontainers/runc/commit/de87203e625cd7a27141fb5f2ad00a320c69c5e8","https://github.com/opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480","https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-52565","description":"runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting `/dev/pts/$n` to `/dev/console` inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of `/dev/pts/$n` to `/dev/console` as configured for all containers that allocate a console). This happens after `pivot_root(2)`, so this cannot be used to write to host files directly -- however, as with CVE-2025-31133, this can load to denial of service of the host or a container breakout by providing the attacker with a writable copy of `/proc/sysrq-trigger` or `/proc/sys/kernel/core_pattern` (respectively). This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3."}]},{"artifact":{"id":"928e44e5e603a57e","cpes":["cpe:2.3:a:opencontainers:runc:v1.1.14:*:*:*:*:*:*:*"],"name":"github.com/opencontainers/runc","purl":"pkg:golang/github.com/opencontainers/runc@v1.1.14","type":"go-module","version":"v1.1.14","language":"go","licenses":[],"metadata":{"h1Digest":"h1:rgSuzbmgz5DUJjeSnw337TxDbRuqjs6iqQck/2weR6w=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.2.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cgrx-mc8f-2prm","versionConstraint":"<=1.2.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/opencontainers/runc","version":"v1.1.14"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-cgrx-mc8f-2prm","fix":{"state":"fixed","versions":["1.2.8"],"available":[{"date":"2025-11-06","kind":"first-observed","version":"1.2.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52881","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-52881","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-52881","date":"2026-10-08","epss":0.00567,"percentile":0.45258}],"risk":0.41957999999999995,"urls":["https://github.com/opencontainers/runc/security/advisories/GHSA-fh74-hm69-rqjw","https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm","https://github.com/opencontainers/selinux/pull/237","https://github.com/opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480","https://github.com/opencontainers/runc/commit/ff6fe1324663538167eca8b3d3eec61e1bd4fa51","https://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3","https://github.com/opencontainers/runc/commit/ed6b1693b8b3ae7eb0250a7e76fc888cdacf98c1","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://github.com/opencontainers/runc/commit/d61fd29d854b416feaaf128bf650325cd2182165","https://github.com/opencontainers/runc/commit/d40b3439a9614a86e87b81a94c6811ec6fa2d7d2","https://github.com/opencontainers/runc/commit/b3dd1bc562ed9996d1a0f249e056c16624046d28","https://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322","https://github.com/opencontainers/runc/commit/77d217c7c3775d8ca5af89e477e81568ef4572db","https://github.com/opencontainers/runc/commit/77889b56db939c323d29d1130f28f9aea2edb544","https://github.com/opencontainers/runc/commit/6fc191449109ea14bb7d61238f24a33fe08c651f","https://github.com/opencontainers/runc/commit/4b37cd93f86e72feac866442988b549b5b7bf3e6","https://github.com/opencontainers/runc/commit/44a0fcf685db051c80b8c269812bb177f5802c58","https://github.com/opencontainers/runc/commit/435cc81be6b79cdec73b4002c0dae549b2f6ae6d","https://github.com/opencontainers/runc/commit/3f925525b44d247e390e529e772a0dc0c0bc3557","https://pkg.go.dev/github.com/cyphar/filepath-securejoin/pathrs-lite/procfs","https://youtu.be/tGseJW_uBB8","https://youtu.be/y1PaBzxwRWQ","https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r","https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2","https://nvd.nist.gov/vuln/detail/CVE-2025-52881","https://github.com/opencontainers/runc/blob/v1.4.0-rc.2/RELEASES.md","http://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322","http://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3","https://github.com/opencontainers/selinux/releases/tag/v1.13.0"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cgrx-mc8f-2prm","description":"runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects"},"relatedVulnerabilities":[{"id":"CVE-2025-52881","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52881","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-52881","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-52881","date":"2026-10-08","epss":0.00567,"percentile":0.45258}],"urls":["http://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322","http://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3","https://github.com/opencontainers/runc/blob/v1.4.0-rc.2/RELEASES.md","https://github.com/opencontainers/runc/commit/3f925525b44d247e390e529e772a0dc0c0bc3557","https://github.com/opencontainers/runc/commit/435cc81be6b79cdec73b4002c0dae549b2f6ae6d","https://github.com/opencontainers/runc/commit/44a0fcf685db051c80b8c269812bb177f5802c58","https://github.com/opencontainers/runc/commit/4b37cd93f86e72feac866442988b549b5b7bf3e6","https://github.com/opencontainers/runc/commit/6fc191449109ea14bb7d61238f24a33fe08c651f","https://github.com/opencontainers/runc/commit/77889b56db939c323d29d1130f28f9aea2edb544","https://github.com/opencontainers/runc/commit/77d217c7c3775d8ca5af89e477e81568ef4572db","https://github.com/opencontainers/runc/commit/b3dd1bc562ed9996d1a0f249e056c16624046d28","https://github.com/opencontainers/runc/commit/d40b3439a9614a86e87b81a94c6811ec6fa2d7d2","https://github.com/opencontainers/runc/commit/d61fd29d854b416feaaf128bf650325cd2182165","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://github.com/opencontainers/runc/commit/ed6b1693b8b3ae7eb0250a7e76fc888cdacf98c1","https://github.com/opencontainers/runc/commit/ff6fe1324663538167eca8b3d3eec61e1bd4fa51","https://github.com/opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480","https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2","https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm","https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-52881","description":"runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3."}]},{"artifact":{"id":"e30002324d8377dd","cpes":["cpe:2.3:a:opencontainers:selinux:v1.12.0:*:*:*:*:*:*:*"],"name":"github.com/opencontainers/selinux","purl":"pkg:golang/github.com/opencontainers/selinux@v1.12.0","type":"go-module","version":"v1.12.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:6n5JV4Cf+4y0KNXW48TLj5DwfXpvWlxXplUkdTrmPb8=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.13.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cgrx-mc8f-2prm","versionConstraint":"<=1.12.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/opencontainers/selinux","version":"v1.12.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-cgrx-mc8f-2prm","fix":{"state":"fixed","versions":["1.13.0"],"available":[{"date":"2025-11-08","kind":"first-observed","version":"1.13.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52881","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-52881","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-52881","date":"2026-10-08","epss":0.00567,"percentile":0.45258}],"risk":0.41957999999999995,"urls":["https://github.com/opencontainers/runc/security/advisories/GHSA-fh74-hm69-rqjw","https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm","https://github.com/opencontainers/selinux/pull/237","https://github.com/opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480","https://github.com/opencontainers/runc/commit/ff6fe1324663538167eca8b3d3eec61e1bd4fa51","https://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3","https://github.com/opencontainers/runc/commit/ed6b1693b8b3ae7eb0250a7e76fc888cdacf98c1","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://github.com/opencontainers/runc/commit/d61fd29d854b416feaaf128bf650325cd2182165","https://github.com/opencontainers/runc/commit/d40b3439a9614a86e87b81a94c6811ec6fa2d7d2","https://github.com/opencontainers/runc/commit/b3dd1bc562ed9996d1a0f249e056c16624046d28","https://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322","https://github.com/opencontainers/runc/commit/77d217c7c3775d8ca5af89e477e81568ef4572db","https://github.com/opencontainers/runc/commit/77889b56db939c323d29d1130f28f9aea2edb544","https://github.com/opencontainers/runc/commit/6fc191449109ea14bb7d61238f24a33fe08c651f","https://github.com/opencontainers/runc/commit/4b37cd93f86e72feac866442988b549b5b7bf3e6","https://github.com/opencontainers/runc/commit/44a0fcf685db051c80b8c269812bb177f5802c58","https://github.com/opencontainers/runc/commit/435cc81be6b79cdec73b4002c0dae549b2f6ae6d","https://github.com/opencontainers/runc/commit/3f925525b44d247e390e529e772a0dc0c0bc3557","https://pkg.go.dev/github.com/cyphar/filepath-securejoin/pathrs-lite/procfs","https://youtu.be/tGseJW_uBB8","https://youtu.be/y1PaBzxwRWQ","https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r","https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2","https://nvd.nist.gov/vuln/detail/CVE-2025-52881","https://github.com/opencontainers/runc/blob/v1.4.0-rc.2/RELEASES.md","http://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322","http://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3","https://github.com/opencontainers/selinux/releases/tag/v1.13.0"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cgrx-mc8f-2prm","description":"runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects"},"relatedVulnerabilities":[{"id":"CVE-2025-52881","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-52881","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2025-52881","cwe":"CWE-363","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-52881","date":"2026-10-08","epss":0.00567,"percentile":0.45258}],"urls":["http://github.com/opencontainers/runc/commit/a41366e74080fa9f26a2cd3544e2801449697322","http://github.com/opencontainers/runc/commit/fdcc9d3cad2f85954a241ccb910a61aaa1ef47f3","https://github.com/opencontainers/runc/blob/v1.4.0-rc.2/RELEASES.md","https://github.com/opencontainers/runc/commit/3f925525b44d247e390e529e772a0dc0c0bc3557","https://github.com/opencontainers/runc/commit/435cc81be6b79cdec73b4002c0dae549b2f6ae6d","https://github.com/opencontainers/runc/commit/44a0fcf685db051c80b8c269812bb177f5802c58","https://github.com/opencontainers/runc/commit/4b37cd93f86e72feac866442988b549b5b7bf3e6","https://github.com/opencontainers/runc/commit/6fc191449109ea14bb7d61238f24a33fe08c651f","https://github.com/opencontainers/runc/commit/77889b56db939c323d29d1130f28f9aea2edb544","https://github.com/opencontainers/runc/commit/77d217c7c3775d8ca5af89e477e81568ef4572db","https://github.com/opencontainers/runc/commit/b3dd1bc562ed9996d1a0f249e056c16624046d28","https://github.com/opencontainers/runc/commit/d40b3439a9614a86e87b81a94c6811ec6fa2d7d2","https://github.com/opencontainers/runc/commit/d61fd29d854b416feaaf128bf650325cd2182165","https://github.com/opencontainers/runc/commit/db19bbed5348847da433faa9d69e9f90192bfa64","https://github.com/opencontainers/runc/commit/ed6b1693b8b3ae7eb0250a7e76fc888cdacf98c1","https://github.com/opencontainers/runc/commit/ff6fe1324663538167eca8b3d3eec61e1bd4fa51","https://github.com/opencontainers/runc/commit/ff94f9991bd32076c871ef0ad8bc1b763458e480","https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2","https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm","https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-52881","description":"runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4.0-rc.3."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34180","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-34180","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"risk":0.3933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-34180"},"relatedVulnerabilities":[{"id":"CVE-2026-34180","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"urls":["https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d","https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83","https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff","https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43","https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-34180","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-34180","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"risk":0.3933,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-34180"},"relatedVulnerabilities":[{"id":"CVE-2026-34180","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"urls":["https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d","https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83","https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff","https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43","https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6355","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6355","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"risk":0.375,"urls":["https://go.dev/cl/826524","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81317","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.\n\nNow, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."},"relatedVulnerabilities":[{"id":"CVE-2026-56855","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"urls":["https://go.dev/cl/826524","https://go.dev/issue/81317","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56855","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."}]},{"artifact":{"id":"9a7a998a24abee58","cpes":["cpe:2.3:a:go-git:go-billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_billy\\/v5:v5.6.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-billy/v5","purl":"pkg:golang/github.com/go-git/go-billy/v5@v5.6.1","type":"go-module","version":"v5.6.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:u+dcrgaguSSkbjzHwelEjc0Yj300NUevrrPphk/SoRA=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qw64-3x98-g7q2","versionConstraint":"<5.9.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-billy/v5","version":"v5.6.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qw64-3x98-g7q2","fix":{"state":"fixed","versions":["5.9.0"],"available":[{"date":"2026-05-15","kind":"first-observed","version":"5.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44973","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44973","date":"2026-10-08","epss":0.00468,"percentile":0.38504}],"risk":0.36504000000000003,"urls":["https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2","https://github.com/go-git/go-billy/releases/tag/v5.9.0","https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1","https://nvd.nist.gov/vuln/detail/CVE-2026-44973"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qw64-3x98-g7q2","description":"go-billy has path traversal vulnerabilities"},"relatedVulnerabilities":[{"id":"CVE-2026-44973","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44973","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44973","date":"2026-10-08","epss":0.00468,"percentile":0.38504}],"urls":["https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44973","description":"Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsistent across some of the built-in implementations. This results in scenarios where applications relying on go-billy for some level of isolation may inadvertently expose access to unintended filesystem locations. This vulnerability is fixed in 5.9.0."}]},{"artifact":{"id":"664b39b795e9aed5","cpes":["cpe:2.3:a:open-telemetry:opentelemetry-collector-contrib\\/extension\\/bearertokenauthextension:v0.96.0:*:*:*:*:*:*:*","cpe:2.3:a:open-telemetry:opentelemetry_collector_contrib\\/extension\\/bearertokenauthextension:v0.96.0:*:*:*:*:*:*:*","cpe:2.3:a:open_telemetry:opentelemetry-collector-contrib\\/extension\\/bearertokenauthextension:v0.96.0:*:*:*:*:*:*:*","cpe:2.3:a:open_telemetry:opentelemetry_collector_contrib\\/extension\\/bearertokenauthextension:v0.96.0:*:*:*:*:*:*:*","cpe:2.3:a:open:opentelemetry-collector-contrib\\/extension\\/bearertokenauthextension:v0.96.0:*:*:*:*:*:*:*","cpe:2.3:a:open:opentelemetry_collector_contrib\\/extension\\/bearertokenauthextension:v0.96.0:*:*:*:*:*:*:*"],"name":"github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension","purl":"pkg:golang/github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension@v0.96.0","type":"go-module","version":"v0.96.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:BM3CZHNvO8p132nrpgutwego0073LCIYOl/u6BbpGdg=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.107.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rfxf-mf63-cpqv","versionConstraint":">=0.80.0,<0.107.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/open-telemetry/opentelemetry-collector-contrib/extension/bearertokenauthextension","version":"v0.96.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-rfxf-mf63-cpqv","fix":{"state":"fixed","versions":["0.107.0"],"available":[{"date":"2024-08-15","kind":"first-observed","version":"0.107.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-42368","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-42368","date":"2026-10-08","epss":0.0062,"percentile":0.48099}],"risk":0.36269999999999997,"urls":["https://github.com/open-telemetry/opentelemetry-collector-contrib/security/advisories/GHSA-rfxf-mf63-cpqv","https://github.com/open-telemetry/opentelemetry-collector-contrib/pull/34516","https://github.com/open-telemetry/opentelemetry-collector-contrib/commit/c9bd3eff0bb357d9c812a0d8defd3b09db95699a","https://nvd.nist.gov/vuln/detail/CVE-2024-42368"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rfxf-mf63-cpqv","description":"open-telemetry has an Observable Timing Discrepancy"},"relatedVulnerabilities":[{"id":"CVE-2024-42368","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-42368","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-42368","date":"2026-10-08","epss":0.0062,"percentile":0.48099}],"urls":["https://github.com/open-telemetry/opentelemetry-collector-contrib/commit/c9bd3eff0bb357d9c812a0d8defd3b09db95699a","https://github.com/open-telemetry/opentelemetry-collector-contrib/pull/34516","https://github.com/open-telemetry/opentelemetry-collector-contrib/security/advisories/GHSA-rfxf-mf63-cpqv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-42368","description":"OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. The bearertokenauth extension's server authenticator performs a simple, non-constant time string comparison of the received & configured bearer tokens. This impacts anyone using the `bearertokenauth` server authenticator. Malicious clients with network access to the collector may perform a timing attack against a collector with this authenticator to guess the configured token, by iteratively sending tokens and comparing the response time. This would allow an attacker to introduce fabricated or bad data into the collector's telemetry pipeline. The observable timing vulnerability was fixed by using constant-time comparison in  0.107.0"}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5450"},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5450"},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"7253ad92559632bb","cpes":["cpe:2.3:a:golang:text:v0.31.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.31.0","type":"go-module","version":"v0.31.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:aC8ghyu4JhP8VojJ2lEHBnochRno1sgL6nEi9WGFGMM=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.39.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5970","versionConstraint":"<0.39.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.31.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5970","fix":{"state":"fixed","versions":["0.39.0"],"available":[{"date":"2026-06-30","kind":"release","version":"0.39.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"risk":0.35624999999999996,"urls":["https://go.dev/cl/794100"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80142","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-56852","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56852","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56852","date":"2026-10-08","epss":0.00475,"percentile":0.39076}],"urls":["https://go.dev/cl/794100","https://go.dev/issue/80142","https://pkg.go.dev/vuln/GO-2026-5970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56852","description":"A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45445","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45445","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865}],"risk":0.35200000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45445"},"relatedVulnerabilities":[{"id":"CVE-2026-45445","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865}],"urls":["https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451","https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7","https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af","https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c","https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45445","description":"Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45445","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45445","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865}],"risk":0.35200000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45445"},"relatedVulnerabilities":[{"id":"CVE-2026-45445","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865}],"urls":["https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451","https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7","https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af","https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c","https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45445","description":"Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-78mq-xcr3-xm33","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-78mq-xcr3-xm33","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39835","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39835","cwe":"CWE-476","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39835","date":"2026-10-08","epss":0.00662,"percentile":0.50108}],"risk":0.34093,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39835","https://go.dev/cl/781660","https://go.dev/issue/79563","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5015","https://access.redhat.com/security/cve/CVE-2026-39835","https://bugzilla.redhat.com/show_bug.cgi?id=2480680","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:51036","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-78mq-xcr3-xm33","description":"golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow"},"relatedVulnerabilities":[{"id":"CVE-2026-39835","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39835","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39835","cwe":"CWE-476","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39835","date":"2026-10-08","epss":0.00662,"percentile":0.50108}],"urls":["https://go.dev/cl/781660","https://go.dev/issue/79563","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5015","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51036","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-39835","https://bugzilla.redhat.com/show_bug.cgi?id=2480680","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39835","description":"SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil."}]},{"artifact":{"id":"adc014ee755a970f","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.3-2build1:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.10.3-2build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.10.3-2build1","language":"","licenses":["sha256:40162167dff80843a4b24aa8d0a4ffc50be5338d004ebe38f86ae3397ba9de3e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.10.3-2ubuntu0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2236","versionConstraint":"< 1.10.3-2ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libgcrypt20","version":"1.10.3-2build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-2236","fix":{"state":"fixed","versions":["1.10.3-2ubuntu0.2"],"available":[{"date":"2026-09-01","kind":"advisory","version":"1.10.3-2ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-08","epss":0.01114,"percentile":0.65005}],"risk":0.3342,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-2236"},"relatedVulnerabilities":[{"id":"CVE-2024-2236","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-08","epss":0.01114,"percentile":0.65005}],"urls":["https://access.redhat.com/errata/RHSA-2024:9404","https://access.redhat.com/errata/RHSA-2025:3530","https://access.redhat.com/errata/RHSA-2025:3534","https://access.redhat.com/security/cve/CVE-2024-2236","https://bugzilla.redhat.com/show_bug.cgi?id=2245218","https://bugzilla.redhat.com/show_bug.cgi?id=2268268"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42766","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42766","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"risk":0.333,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42766"},"relatedVulnerabilities":[{"id":"CVE-2026-42766","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"urls":["https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce","https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4","https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7","https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4","https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42766","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42766","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"risk":0.333,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42766"},"relatedVulnerabilities":[{"id":"CVE-2026-42766","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"urls":["https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce","https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4","https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7","https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4","https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4046"},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"risk":0.331,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4046"},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6303","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6303","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56854","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56854","date":"2026-10-08","epss":0.00437,"percentile":0.36015}],"risk":0.32775,"urls":["https://go.dev/cl/797040"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80213","description":"The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback."},"relatedVulnerabilities":[{"id":"CVE-2026-56854","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56854","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56854","date":"2026-10-08","epss":0.00437,"percentile":0.36015}],"urls":["https://go.dev/cl/797040","https://go.dev/issue/80213","https://pkg.go.dev/vuln/GO-2026-6303"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56854","description":"The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6354","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6354","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"risk":0.32325,"urls":["https://go.dev/cl/826504","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81316","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.\n\nNow, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."},"relatedVulnerabilities":[{"id":"CVE-2026-78662","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"urls":["https://go.dev/cl/826504","https://go.dev/issue/81316","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6354"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78662","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5419","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5419","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5419","date":"2026-10-08","epss":0.0063,"percentile":0.48546}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5419"},"relatedVulnerabilities":[{"id":"CVE-2026-5419","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5419","date":"2026-10-08","epss":0.0063,"percentile":0.48546}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5419","https://bugzilla.redhat.com/show_bug.cgi?id=2467686","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5419","description":"A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure."}]},{"artifact":{"id":"9a7a998a24abee58","cpes":["cpe:2.3:a:go-git:go-billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-billy\\/v5:v5.6.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_billy\\/v5:v5.6.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-billy/v5","purl":"pkg:golang/github.com/go-git/go-billy/v5@v5.6.1","type":"go-module","version":"v5.6.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:u+dcrgaguSSkbjzHwelEjc0Yj300NUevrrPphk/SoRA=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m3xc-h892-ggx6","versionConstraint":"<5.9.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-billy/v5","version":"v5.6.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-m3xc-h892-ggx6","fix":{"state":"fixed","versions":["5.9.0"],"available":[{"date":"2026-05-13","kind":"first-observed","version":"5.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44740","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44740","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44740","date":"2026-10-08","epss":0.0053,"percentile":0.43047}],"risk":0.30474999999999997,"urls":["https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6","https://github.com/go-git/go-billy/releases/tag/v5.9.0","https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1","https://nvd.nist.gov/vuln/detail/CVE-2026-44740"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m3xc-h892-ggx6","description":"go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-44740","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44740","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44740","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44740","date":"2026-10-08","epss":0.0053,"percentile":0.43047}],"urls":["https://github.com/go-git/go-billy/releases/tag/v5.9.0","https://github.com/go-git/go-billy/releases/tag/v6.0.0-alpha.1","https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44740","description":"Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-45gg-vh54-h5m9","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-45gg-vh54-h5m9","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39828","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39828","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39828","date":"2026-10-08","epss":0.00539,"percentile":0.43577}],"risk":0.30453499999999994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39828","https://go.dev/cl/781621","https://go.dev/issue/79562","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5014","https://access.redhat.com/security/cve/CVE-2026-39828","https://bugzilla.redhat.com/show_bug.cgi?id=2480687","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40119","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41055"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-45gg-vh54-h5m9","description":"golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions"},"relatedVulnerabilities":[{"id":"CVE-2026-39828","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39828","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39828","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39828","date":"2026-10-08","epss":0.00539,"percentile":0.43577}],"urls":["https://go.dev/cl/781621","https://go.dev/issue/79562","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5014","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-39828","https://bugzilla.redhat.com/show_bug.cgi?id=2480687","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39828","description":"When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48959","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-48959","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"risk":0.3045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48959"},"relatedVulnerabilities":[{"id":"CVE-2026-48959","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48959","cwe":"CWE-407","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-48959","date":"2026-10-08","epss":0.00609,"percentile":0.47546}],"urls":["https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48959","description":"IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.\n\nfastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.\n\nExtracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap."}]},{"artifact":{"id":"6860f54cb4c4abbc","cpes":["cpe:2.3:a:docker:docker:v25.0.6\\+incompatible:*:*:*:*:*:*:*"],"name":"github.com/docker/docker","purl":"pkg:golang/github.com/docker/docker@v25.0.6%2Bincompatible","type":"go-module","version":"v25.0.6+incompatible","language":"go","licenses":[],"metadata":{"h1Digest":"h1:5cPwbwriIcsua2REJe8HqQV+6WlWc1byg2QSXzBxBGg=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pxq6-2prw-chj9","versionConstraint":"<29.3.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/docker/docker","version":"v25.0.6+incompatible"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-pxq6-2prw-chj9","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33997","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33997","cwe":"CWE-266","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33997","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.30208,"urls":["https://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9","https://github.com/moby/moby/commit/f4d6f25bf0c3fa12d4968320a45685947756a22a","https://docs.docker.com/engine/extend/legacy_plugins","https://github.com/moby/moby/releases/tag/docker-v29.3.1","https://nvd.nist.gov/vuln/detail/CVE-2026-33997"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pxq6-2prw-chj9","description":"Moby has an Off-by-one error in its plugin privilege validation"},"relatedVulnerabilities":[{"id":"CVE-2026-33997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33997","cwe":"CWE-193","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-33997","cwe":"CWE-266","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33997","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://github.com/moby/moby/releases/tag/docker-v29.3.1","https://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/security/cve/CVE-2026-33997","https://bugzilla.redhat.com/show_bug.cgi?id=2453277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33997.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33997","description":"Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.2925,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84782"},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.2925,"urls":[],"severity":"High","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84782"},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9076","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-9076","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"risk":0.2919,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-9076"},"relatedVulnerabilities":[{"id":"CVE-2026-9076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"urls":["https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb","https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0","https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98","https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26","https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9076","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-9076","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"risk":0.2919,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-9076"},"relatedVulnerabilities":[{"id":"CVE-2026-9076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"urls":["https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb","https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0","https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98","https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26","https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42011","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42011","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42011","date":"2026-10-08","epss":0.0057,"percentile":0.45419}],"risk":0.28500000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42011"},"relatedVulnerabilities":[{"id":"CVE-2026-42011","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42011","date":"2026-10-08","epss":0.0057,"percentile":0.45419}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42011","https://bugzilla.redhat.com/show_bug.cgi?id=2467437","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42011","description":"A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.28289999999999993,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28387"},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.28289999999999993,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28387"},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"6ef02dd49ce06248","cpes":["cpe:2.3:a:gzip:gzip:1.12-1ubuntu3.1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/ubuntu/gzip@1.12-1ubuntu3.1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.12-1ubuntu3.1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.list"},{"path":"/var/lib/dpkg/info/gzip.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.postinst"},{"path":"/var/lib/dpkg/info/gzip.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.12-1ubuntu3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41992","versionConstraint":"< 1.12-1ubuntu3.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gzip","version":"1.12-1ubuntu3.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41992","fix":{"state":"fixed","versions":["1.12-1ubuntu3.2"],"available":[{"date":"2026-07-06","kind":"advisory","version":"1.12-1ubuntu3.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"risk":0.28200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41992"},"relatedVulnerabilities":[{"id":"CVE-2026-41992","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41992","cwe":"CWE-126","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41992","date":"2026-10-08","epss":0.00564,"percentile":0.4513}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=e7378c2d421be6a286922374425680bbe9ad8b7d","https://www.gnu.org/software/gzip/","http://www.openwall.com/lists/oss-security/2026/08/23/1","http://www.openwall.com/lists/oss-security/2026/08/25/1","http://www.openwall.com/lists/oss-security/2026/08/27/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41992","description":"GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation.\nBy decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.\n\nThis issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42013","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42013","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42013","date":"2026-10-08","epss":0.00564,"percentile":0.45129}],"risk":0.28200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42013"},"relatedVulnerabilities":[{"id":"CVE-2026-42013","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42013","date":"2026-10-08","epss":0.00564,"percentile":0.45129}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42013","https://bugzilla.redhat.com/show_bug.cgi?id=2467448","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42013","description":"A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4946","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4946","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"risk":0.26625,"urls":["https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758061","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.\n\nThis only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},"relatedVulnerabilities":[{"id":"CVE-2026-32281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"urls":["https://go.dev/cl/758061","https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4946"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9m57-25v3-79x9","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-9m57-25v3-79x9","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46598","cwe":"CWE-129","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46598","date":"2026-10-08","epss":0.00515,"percentile":0.42036}],"risk":0.265225,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-46598","https://go.dev/cl/781360","https://go.dev/issue/79596","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5033"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9m57-25v3-79x9","description":"golang.org/x/crypto: Invoking pathological inputs can lead to client panic"},"relatedVulnerabilities":[{"id":"CVE-2026-46598","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46598","cwe":"CWE-129","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46598","date":"2026-10-08","epss":0.00515,"percentile":0.42036}],"urls":["https://go.dev/cl/781360","https://go.dev/issue/79596","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5033"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46598","description":"For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5cv4-jp36-h3mw","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-5cv4-jp36-h3mw","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-07-02","kind":"first-observed","version":"0.55.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25680","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25680","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"risk":0.26449999999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-25680","https://go.dev/cl/781702","https://go.dev/issue/79573","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5028","https://go.googlesource.com/net/+/08be507abce89191d78cd49da60f4501fc910472","https://go.googlesource.com/net/+/refs/tags/v0.55.0"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5cv4-jp36-h3mw","description":"Go Net HTML parser is vulnerable to denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-25680","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25680","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25680","date":"2026-10-08","epss":0.0046,"percentile":0.37848}],"urls":["https://go.dev/cl/781702","https://go.dev/issue/79573","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5028"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25680","description":"Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.19.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hc8v-wwc9-vgxm","versionConstraint":"<=5.19.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-hc8v-wwc9-vgxm","fix":{"state":"fixed","versions":["5.19.2"],"available":[{"date":"2026-08-08","kind":"first-observed","version":"5.19.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71556","cwe":"CWE-59","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71556","date":"2026-10-08","epss":0.00357,"percentile":0.27395}],"risk":0.26060999999999995,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm","https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab","https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac","https://github.com/go-git/go-git/releases/tag/v5.19.2","https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hc8v-wwc9-vgxm","description":"go-git: Worktree operations may follow symlinks"},"relatedVulnerabilities":[{"id":"CVE-2026-71556","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71556","cwe":"CWE-59","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71556","date":"2026-10-08","epss":0.00357,"percentile":0.27395}],"urls":["https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab","https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac","https://github.com/go-git/go-git/releases/tag/v5.19.2","https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5","https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71556","description":"go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5."}]},{"artifact":{"id":"8f4cf9baab26d4f0","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.5?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.5.3-5ubuntu5.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"< 1.5.3-5ubuntu5.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"fixed","versions":["1.5.3-5ubuntu5.6"],"available":[{"date":"2026-07-23","kind":"advisory","version":"1.5.3-5ubuntu5.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"c322cb2c91836caa","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.5?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.5.3-5ubuntu5.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"< 1.5.3-5ubuntu5.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"fixed","versions":["1.5.3-5ubuntu5.6"],"available":[{"date":"2026-07-23","kind":"advisory","version":"1.5.3-5ubuntu5.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"d04a485a523784c8","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.5?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.5.3-5ubuntu5.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"< 1.5.3-5ubuntu5.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"fixed","versions":["1.5.3-5ubuntu5.6"],"available":[{"date":"2026-07-23","kind":"advisory","version":"1.5.3-5ubuntu5.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"9aa31bc48b99a584","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.5?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.5.3-5ubuntu5.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"< 1.5.3-5ubuntu5.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"fixed","versions":["1.5.3-5ubuntu5.6"],"available":[{"date":"2026-07-23","kind":"advisory","version":"1.5.3-5ubuntu5.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.25,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54411"},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48962","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-48962","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"risk":0.24750000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-48962"},"relatedVulnerabilities":[{"id":"CVE-2026-48962","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48962","cwe":"CWE-95","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-48962","cwe":"CWE-94","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-48962","date":"2026-10-08","epss":0.00495,"percentile":0.40582}],"urls":["https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610.patch","https://metacpan.org/release/PMQS/IO-Compress-2.220/changes","http://www.openwall.com/lists/oss-security/2026/05/27/4","https://access.redhat.com/errata/RHSA-2026:29182","https://access.redhat.com/errata/RHSA-2026:29210","https://access.redhat.com/errata/RHSA-2026:29867","https://access.redhat.com/errata/RHSA-2026:29941","https://access.redhat.com/errata/RHSA-2026:30085","https://access.redhat.com/errata/RHSA-2026:30086","https://access.redhat.com/errata/RHSA-2026:30115","https://access.redhat.com/errata/RHSA-2026:30843","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30858","https://access.redhat.com/errata/RHSA-2026:30859","https://access.redhat.com/errata/RHSA-2026:30860","https://access.redhat.com/errata/RHSA-2026:50262","https://access.redhat.com/security/cve/CVE-2026-48962","https://bugzilla.redhat.com/show_bug.cgi?id=2481767","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48962.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48962","description":"IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.\n\n_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.\n\nArbitrary Perl in the output glob executes at the calling process's privilege."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5928"},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5928"},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"059ac6c07034f18c","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3build1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3build1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.35+dfsg-3ubuntu0.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-45582","versionConstraint":"< 1.35+dfsg-3ubuntu0.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-45582","fix":{"state":"fixed","versions":["1.35+dfsg-3ubuntu0.2"],"available":[{"date":"2026-07-06","kind":"advisory","version":"1.35+dfsg-3ubuntu0.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-45582","cwe":"CWE-24","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-45582","date":"2026-10-08","epss":0.00489,"percentile":0.40122}],"risk":0.24450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-45582"},"relatedVulnerabilities":[{"id":"CVE-2025-45582","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":2.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-45582","cwe":"CWE-24","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-45582","date":"2026-10-08","epss":0.00489,"percentile":0.40122}],"urls":["https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md","https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html","https://www.gnu.org/software/tar/","https://www.gnu.org/software/tar/manual/html_node/Integrity.html","https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html","http://www.openwall.com/lists/oss-security/2025/11/01/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-45582","description":"GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of \"Member name contains '..'\" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain \"x -> ../../../../../home/victim/.ssh\" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which \"tar xf\" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each \"tar xf\" in its Security Rules of Thumb; however, third-party advice leads users to run \"tar xf\" more than once into the same directory."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42012","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42012","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42012","date":"2026-10-08","epss":0.00487,"percentile":0.3999}],"risk":0.24350000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42012"},"relatedVulnerabilities":[{"id":"CVE-2026-42012","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42012","date":"2026-10-08","epss":0.00487,"percentile":0.3999}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42012","https://bugzilla.redhat.com/show_bug.cgi?id=2467441","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42012","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28390","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28390","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"risk":0.2415,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28390"},"relatedVulnerabilities":[{"id":"CVE-2026-28390","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"urls":["https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc","https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6","https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4","https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788","https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-28390","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-28390","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"risk":0.2415,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-28390"},"relatedVulnerabilities":[{"id":"CVE-2026-28390","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"urls":["https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc","https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6","https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4","https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788","https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8376","versionConstraint":"< 5.38.2-3.2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8376","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.3"],"available":[{"date":"2026-05-26","kind":"advisory","version":"5.38.2-3.2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"risk":0.2405,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8376"},"relatedVulnerabilities":[{"id":"CVE-2026-8376","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8376","cwe":"CWE-680","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-8376","date":"2026-10-08","epss":0.00481,"percentile":0.39502}],"urls":["https://github.com/Perl/perl5/commit/5e7f119eb2bb1181be908701f22bf7068e722f1c.patch","http://www.openwall.com/lists/oss-security/2026/05/26/1"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8376","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.\n\nPerl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.\n\nA caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42497","versionConstraint":"< 5.38.2-3.2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42497","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.3"],"available":[{"date":"2026-05-26","kind":"advisory","version":"5.38.2-3.2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"risk":0.2355,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42497"},"relatedVulnerabilities":[{"id":"CVE-2026-42497","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42497","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42497","cwe":"CWE-732","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-42497","date":"2026-10-08","epss":0.00471,"percentile":0.38728}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42496"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42497","description":"Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.\n\nA subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.19.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qgq7-7hm3-q39j","versionConstraint":"<=5.19.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qgq7-7hm3-q39j","fix":{"state":"fixed","versions":["5.19.2"],"available":[{"date":"2026-08-08","kind":"first-observed","version":"5.19.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":4.3,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71557","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71557","date":"2026-10-08","epss":0.00413,"percentile":0.33583}],"risk":0.233345,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j","https://github.com/go-git/go-git/pull/2247","https://github.com/go-git/go-git/pull/2254","https://github.com/go-git/go-git/commit/4a0e66d555de5f9a30c31e2df64f445f42bd01e7","https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36","https://github.com/go-git/go-git/releases/tag/v5.19.2","https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qgq7-7hm3-q39j","description":"go-git: Malicious reference names may modify files outside the reference storage"},"relatedVulnerabilities":[{"id":"CVE-2026-71557","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":4.3,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71557","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71557","date":"2026-10-08","epss":0.00413,"percentile":0.33583}],"urls":["https://github.com/go-git/go-git/commit/4a0e66d555de5f9a30c31e2df64f445f42bd01e7","https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36","https://github.com/go-git/go-git/pull/2247","https://github.com/go-git/go-git/pull/2254","https://github.com/go-git/go-git/releases/tag/v5.19.2","https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5","https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71557","description":"go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"risk":0.22399999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-9538"},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-08","epss":0.00448,"percentile":0.36971}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.22200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6238"},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.22200000000000003,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6238"},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4980","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4980","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"risk":0.21811499999999998,"urls":["https://go.dev/cl/771180","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78981","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."},"relatedVulnerabilities":[{"id":"CVE-2026-39826","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"urls":["https://go.dev/cl/771180","https://go.dev/issue/78981","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4980"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39826","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13221","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13221","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"risk":0.216,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13221"},"relatedVulnerabilities":[{"id":"CVE-2026-13221","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13221","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-13221","date":"2026-10-08","epss":0.00432,"percentile":0.35531}],"urls":["https://github.com/Perl/perl5/commit/03f74bbbd3a68350d926ee93d56ee4808c28c4c7.patch","https://github.com/Perl/perl5/issues/23388","http://www.openwall.com/lists/oss-security/2026/07/13/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13221","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.\n\nWhen such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.\n\nA pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42496","versionConstraint":"< 5.38.2-3.2ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42496","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.3"],"available":[{"date":"2026-05-26","kind":"advisory","version":"5.38.2-3.2ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"risk":0.215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42496"},"relatedVulnerabilities":[{"id":"CVE-2026-42496","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.2,"impactScore":6.1,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42496","cwe":"CWE-59","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-42496","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42496","date":"2026-10-08","epss":0.0043,"percentile":0.35229}],"urls":["https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.08/changes","https://www.cve.org/CVERecord?id=CVE-2026-42497","https://access.redhat.com/errata/RHSA-2026:30851","https://access.redhat.com/errata/RHSA-2026:30852","https://access.redhat.com/errata/RHSA-2026:30856","https://access.redhat.com/errata/RHSA-2026:30857","https://access.redhat.com/security/cve/CVE-2026-42496","https://bugzilla.redhat.com/show_bug.cgi?id=2481314","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42496.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42496","description":"Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.\n\n_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.\n\nA subsequent open through the extracted name reads or writes the attacker chosen path."}]},{"artifact":{"id":"ec3b43637a287302","cpes":["cpe:2.3:a:dpkg:dpkg:1.22.6ubuntu6.5:*:*:*:*:*:*:*"],"name":"dpkg","purl":"pkg:deb/ubuntu/dpkg@1.22.6ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.22.6ubuntu6.5","language":"","licenses":["GPL-2","GPL-2+","public-domain-s-s-d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dpkg/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/dpkg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dpkg.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dpkg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dpkg.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dpkg.list"},{"path":"/var/lib/dpkg/info/dpkg.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dpkg.postinst"},{"path":"/var/lib/dpkg/info/dpkg.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dpkg.postrm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.22.6ubuntu6.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-2219","versionConstraint":"< 1.22.6ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dpkg","version":"1.22.6ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-2219","fix":{"state":"fixed","versions":["1.22.6ubuntu6.6"],"available":[{"date":"2026-05-07","kind":"advisory","version":"1.22.6ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-2219","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-2219","date":"2026-10-08","epss":0.00426,"percentile":0.34821}],"risk":0.213,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-2219"},"relatedVulnerabilities":[{"id":"CVE-2026-2219","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2219","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-2219","date":"2026-10-08","epss":0.00426,"percentile":0.34821}],"urls":["https://bugs.debian.org/1129722","https://git.dpkg.org/cgit/dpkg/dpkg.git/commit/?id=6610297a62c0780dd0e80b0e302ef64fdcc9d313"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2219","description":"It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU)."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4976","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4976","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"risk":0.212695,"urls":["https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/770541","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions.\n\nWhen used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function.\n\nFor example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."},"relatedVulnerabilities":[{"id":"CVE-2026-39825","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"urls":["https://go.dev/cl/770541","https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4976"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39825","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"c95b384f90bfaa01","cpes":["cpe:2.3:a:grafana:loki:v1.6.2-0.20240510183741-cef4c2826b4b:*:*:*:*:*:*:*"],"name":"github.com/grafana/loki","purl":"pkg:golang/github.com/grafana/loki@v1.6.2-0.20240510183741-cef4c2826b4b","type":"go-module","version":"v1.6.2-0.20240510183741-cef4c2826b4b","language":"go","licenses":[],"metadata":{"h1Digest":"h1:x5JsSnExxRl9kTMNqHebMCv0fn+V1+T16z7Tgz6xYf4=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5115","versionConstraint":"none (unknown)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/grafana/loki","version":"v1.6.2-0.20240510183741-cef4c2826b4b"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5115","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"security@grafana.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21726","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-21726","date":"2026-10-08","epss":0.00409,"percentile":0.3311}],"risk":0.210635,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-21726","https://grafana.com/security/security-advisories/cve-2026-21726"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-497x-rrr9-68jp","description":"Grafana Loki Path Traversal - CVE-2021-36156 Bypass in github.com/grafana/loki"},"relatedVulnerabilities":[{"id":"CVE-2026-21726","cvss":[{"type":"Secondary","source":"security@grafana.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21726","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-21726","date":"2026-10-08","epss":0.00409,"percentile":0.3311}],"urls":["https://grafana.com/security/security-advisories/cve-2026-21726"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-21726","description":"The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}\n\nThanks to Prasanth Sundararajan for reporting this vulnerability."},{"id":"GHSA-497x-rrr9-68jp","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21726","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-21726","date":"2026-10-08","epss":0.00409,"percentile":0.3311}],"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-21726","https://grafana.com/security/security-advisories/cve-2026-21726"],"severity":"Medium","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-497x-rrr9-68jp","description":"Grafana Loki Path Traversal - CVE-2021-36156 Bypass"}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7383","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7383","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"risk":0.2103,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7383"},"relatedVulnerabilities":[{"id":"CVE-2026-7383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"urls":["https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6","https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74","https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974","https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083","https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7383","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7383","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"risk":0.2103,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7383"},"relatedVulnerabilities":[{"id":"CVE-2026-7383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"urls":["https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6","https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74","https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974","https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083","https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19487","versionConstraint":"< 5.38.2-3.2ubuntu0.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19487","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.6"],"available":[{"date":"2026-09-16","kind":"advisory","version":"5.38.2-3.2ubuntu0.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"risk":0.209,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19487"},"relatedVulnerabilities":[{"id":"CVE-2026-19487","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19487","cwe":"CWE-670","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-19487","date":"2026-10-08","epss":0.00418,"percentile":0.34114}],"urls":["https://github.com/Perl/perl5/commit/1a21abacaf6f684928bae8baaa153733c8c238eb.patch","https://github.com/Perl/perl5/issues/22892","http://www.openwall.com/lists/oss-security/2026/08/13/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19487","description":"Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.\n\nThe prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.\n\nExample:\n\n  \"ABCDE\" =~ m/ABCF|BCDE|C/;    # matches C at offset 2, not BCDE\n  \"ABCDE\" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed\n\nAn alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-80489"},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-80489"},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77117"},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.20600000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77117"},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"059ac6c07034f18c","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3build1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3build1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.35+dfsg-3ubuntu0.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"< 1.35+dfsg-3ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"fixed","versions":["1.35+dfsg-3ubuntu0.4"],"available":[{"date":"2026-07-22","kind":"advisory","version":"1.35+dfsg-3ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5704"},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5435"},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5435"},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4603","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4603","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"risk":0.19202999999999998,"urls":["https://go.dev/issue/77954","https://go.dev/cl/752081"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\".\n\nA new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."},"relatedVulnerabilities":[{"id":"CVE-2026-27142","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"urls":["https://go.dev/cl/752081","https://go.dev/issue/77954","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4603"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27142","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12087","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12087","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"risk":0.187,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12087"},"relatedVulnerabilities":[{"id":"CVE-2026-12087","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12087","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-12087","cwe":"CWE-805","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-12087","date":"2026-10-08","epss":0.00374,"percentile":0.29283}],"urls":["https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb.patch","https://metacpan.org/release/PEVANS/Socket-2.041/changes","http://www.openwall.com/lists/oss-security/2026/06/15/10"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12087","description":"Socket versions before 2.041 for Perl have an out-of-bounds heap read.\n\nIn Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.\n\nCalling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.1866,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54874"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.1866,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54874"},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5025","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5025","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42506","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42506","date":"2026-10-08","epss":0.00333,"percentile":0.2444}],"risk":0.18481499999999998,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781700"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79571","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-42506","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42506","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42506","date":"2026-10-08","epss":0.00333,"percentile":0.2444}],"urls":["https://go.dev/cl/781700","https://go.dev/issue/79571","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42506","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4865","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4865","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763762","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied.\n\nThese issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."},"relatedVulnerabilities":[{"id":"CVE-2026-32289","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/763762","https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4865"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32289","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4982","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4982","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/cl/769920","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78913","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-39823","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/769920","https://go.dev/issue/78913","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4982"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39823","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57433","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57433","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"risk":0.1785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57433"},"relatedVulnerabilities":[{"id":"CVE-2026-57433","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57433","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57433","date":"2026-10-08","epss":0.00357,"percentile":0.27366}],"urls":["https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7.patch","http://www.openwall.com/lists/oss-security/2026/07/13/7"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57433","description":"Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.\n\nretrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.\n\nA crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization."}]},{"artifact":{"id":"ac4c65178408e21f","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4970","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4970","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"risk":0.17748,"urls":["https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://go.dev/cl/797880"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79005","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.\n\nFor example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."},"relatedVulnerabilities":[{"id":"CVE-2026-39822","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"urls":["https://go.dev/cl/797880","https://go.dev/issue/79005","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-4970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.1764,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-63074"},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-63074","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.1764,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-63074"},"relatedVulnerabilities":[{"id":"CVE-2026-63074","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"fc79954134fe2e5a","cpes":["cpe:2.3:a:google:grpc:v1.67.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.67.1","type":"go-module","version":"v1.67.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:zWnc1Vrcno+lHZCOofnIMvycFcc0QRGIzm9dhnDX68E=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.83.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qc2q-p7wx-3px3","versionConstraint":"<=1.83.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.67.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qc2q-p7wx-3px3","fix":{"state":"fixed","versions":["1.83.1"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"1.83.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84303","cwe":"CWE-178","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84303","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84303","date":"2026-10-08","epss":0.00311,"percentile":0.21971}],"risk":0.17571499999999998,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3","https://nvd.nist.gov/vuln/detail/CVE-2026-84303","https://github.com/grpc/grpc-go/pull/9332","https://github.com/grpc/grpc-go/pull/9335","https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8","https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe","https://github.com/grpc/grpc-go/releases/tag/v1.83.1"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qc2q-p7wx-3px3","description":"gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion"},"relatedVulnerabilities":[{"id":"CVE-2026-84303","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84303","cwe":"CWE-178","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-84303","cwe":"CWE-863","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84303","date":"2026-10-08","epss":0.00311,"percentile":0.21971}],"urls":["https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8","https://github.com/grpc/grpc-go/commit/ebba6f3f1b206e2b4dc4d1d5a96d18430302c2fe","https://github.com/grpc/grpc-go/pull/9332","https://github.com/grpc/grpc-go/pull/9335","https://github.com/grpc/grpc-go/releases/tag/v1.83.1","https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84303","description":"gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"993af967e1703550","cpes":["cpe:2.3:a:liblzma5:liblzma5:5.6.1\\+really5.4.5-1ubuntu0.2:*:*:*:*:*:*:*"],"name":"liblzma5","purl":"pkg:deb/ubuntu/liblzma5@5.6.1%2Breally5.4.5-1ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=xz-utils","type":"deb","version":"5.6.1+really5.4.5-1ubuntu0.2","language":"","licenses":["Autoconf","GPL-2","GPL-2+","GPL-3","LGPL-2","LGPL-2.1","LGPL-2.1+","PD","PD-debian","config-h","noderivs","permissive-fsf","permissive-nowarranty","probably-PD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblzma5/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/liblzma5/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/liblzma5:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"xz-utils"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.6.1+really5.4.5-1ubuntu0.3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34743","versionConstraint":"< 5.6.1+really5.4.5-1ubuntu0.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"xz-utils","version":"5.6.1+really5.4.5-1ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-34743","fix":{"state":"fixed","versions":["5.6.1+really5.4.5-1ubuntu0.3"],"available":[{"date":"2026-06-02","kind":"advisory","version":"5.6.1+really5.4.5-1ubuntu0.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"risk":0.17189999999999997,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-34743"},"relatedVulnerabilities":[{"id":"CVE-2026-34743","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"urls":["https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87","https://github.com/tukaani-project/xz/releases/tag/v5.8.3","https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv","http://www.openwall.com/lists/oss-security/2026/03/31/13","https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34743","description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.19.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-crhj-59gh-8x96","versionConstraint":"<=5.19.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-crhj-59gh-8x96","fix":{"state":"fixed","versions":["5.19.1"],"available":[{"date":"2026-05-19","kind":"first-observed","version":"5.19.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45571","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45571","date":"2026-10-08","epss":0.0033,"percentile":0.24059}],"risk":0.1716,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96","https://nvd.nist.gov/vuln/detail/CVE-2026-45571"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-crhj-59gh-8x96","description":"go-git: Crafted repositories may modify main and submodule .git directories"},"relatedVulnerabilities":[{"id":"CVE-2026-45571","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45571","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45571","date":"2026-10-08","epss":0.0033,"percentile":0.24059}],"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45571","description":"go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4864","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4864","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"risk":0.16644,"urls":["https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763761","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root.\n\nThe Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."},"relatedVulnerabilities":[{"id":"CVE-2026-32282","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"urls":["https://go.dev/cl/763761","https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4864"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32282","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."}]},{"artifact":{"id":"3d2cf63ae2e37d1a","cpes":["cpe:2.3:a:diffutils:diffutils:1\\:3.10-1build1:*:*:*:*:*:*:*"],"name":"diffutils","purl":"pkg:deb/ubuntu/diffutils@1%3A3.10-1build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1:3.10-1build1","language":"","licenses":["FSFAP","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2.0+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3.0+","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/diffutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/diffutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/diffutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/diffutils.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/diffutils.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1:3.10-1ubuntu0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53910","versionConstraint":"< 1:3.10-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"diffutils","version":"1:3.10-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53910","fix":{"state":"fixed","versions":["1:3.10-1ubuntu0.1"],"available":[{"date":"2026-08-31","kind":"advisory","version":"1:3.10-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-08","epss":0.00332,"percentile":0.24312}],"risk":0.166,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53910"},"relatedVulnerabilities":[{"id":"CVE-2026-53910","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53910","cwe":"CWE-190","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-53910","date":"2026-10-08","epss":0.00332,"percentile":0.24312}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-53910","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=73ed7ce85cc78effb94daf028c9af6b4e5252e50","https://cgit.git.savannah.gnu.org/cgit/diffutils.git/commit/?id=9ff04d5b84743e331e80b589335a52c5480d1815","https://git.savannah.gnu.org/cgit/diffutils.git/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53910","description":"diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds.\nWhen processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing. \nAn attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.\n\n\nThis issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 \n\nNOTE:\nThe project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4437","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4437","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-4437","cwe":"CWE-125","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4437","date":"2026-10-08","epss":0.00325,"percentile":0.23534}],"risk":0.1625,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4437"},"relatedVulnerabilities":[{"id":"CVE-2026-4437","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4437","cwe":"CWE-125","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4437","date":"2026-10-08","epss":0.00325,"percentile":0.23534}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34014","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4437","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4437","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4437","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-4437","cwe":"CWE-125","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4437","date":"2026-10-08","epss":0.00325,"percentile":0.23534}],"risk":0.1625,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4437"},"relatedVulnerabilities":[{"id":"CVE-2026-4437","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4437","cwe":"CWE-125","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4437","date":"2026-10-08","epss":0.00325,"percentile":0.23534}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34014","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4437","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer."}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qpw4-5x99-6vjp","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qpw4-5x99-6vjp","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39827","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39827","date":"2026-10-08","epss":0.00281,"percentile":0.18814}],"risk":0.16157499999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39827","https://go.dev/cl/781320","https://go.dev/issue/35127","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5016"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qpw4-5x99-6vjp","description":"golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-39827","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39827","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39827","date":"2026-10-08","epss":0.00281,"percentile":0.18814}],"urls":["https://go.dev/cl/781320","https://go.dev/issue/35127","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39827","description":"An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4438","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4438","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-4438","cwe":"CWE-20","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-4438","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4438","date":"2026-10-08","epss":0.00316,"percentile":0.22521}],"risk":0.158,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4438"},"relatedVulnerabilities":[{"id":"CVE-2026-4438","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4438","cwe":"CWE-20","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-4438","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4438","date":"2026-10-08","epss":0.00316,"percentile":0.22521}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34015","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4438","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.8"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4438","versionConstraint":"< 2.39-0ubuntu8.8 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4438","fix":{"state":"fixed","versions":["2.39-0ubuntu8.8"],"available":[{"date":"2026-07-27","kind":"advisory","version":"2.39-0ubuntu8.8"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-4438","cwe":"CWE-20","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-4438","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4438","date":"2026-10-08","epss":0.00316,"percentile":0.22521}],"risk":0.158,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4438"},"relatedVulnerabilities":[{"id":"CVE-2026-4438","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4438","cwe":"CWE-20","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-4438","cwe":"CWE-88","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4438","date":"2026-10-08","epss":0.00316,"percentile":0.22521}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34015","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4438","description":"Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification."}]},{"artifact":{"id":"a6bbe16f49176f0a","cpes":["cpe:2.3:a:otel:sdk:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/sdk","purl":"pkg:golang/go.opentelemetry.io/otel/sdk@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:YMPPDNymmQN3ZgczicBY3B6sf9n62Dlj9pWD3ucgoDw=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.43.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hfvc-g4fc-pqhx","versionConstraint":">=1.15.0,<=1.42.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/sdk","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-hfvc-g4fc-pqhx","fix":{"state":"fixed","versions":["1.43.0"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"1.43.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39883","cwe":"CWE-426","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39883","cwe":"CWE-426","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39883","date":"2026-10-08","epss":0.00207,"percentile":0.09862}],"risk":0.15317999999999998,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx","http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0","https://nvd.nist.gov/vuln/detail/CVE-2026-39883"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hfvc-g4fc-pqhx","description":"opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking"},"relatedVulnerabilities":[{"id":"CVE-2026-39883","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":6.1,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39883","cwe":"CWE-426","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-39883","cwe":"CWE-426","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39883","date":"2026-10-08","epss":0.00207,"percentile":0.09862}],"urls":["http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx","https://access.redhat.com/errata/RHSA-2026:26254","https://access.redhat.com/errata/RHSA-2026:26257","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/security/cve/CVE-2026-39883","https://bugzilla.redhat.com/show_bug.cgi?id=2456718","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39883.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39883","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0."}]},{"artifact":{"id":"6708751325e2c116","cpes":[],"name":"go.mongodb.org/mongo-driver","purl":"pkg:golang/go.mongodb.org/mongo-driver@v1.12.0","type":"go-module","version":"v1.12.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:aPx33jmn/rQuJXPQLZQ8NtfPQG8CaqgLThFtqRb0PiE=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.17.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cp6g-7hqx-qxhp","versionConstraint":"<1.17.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.mongodb.org/mongo-driver","version":"v1.12.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-cp6g-7hqx-qxhp","fix":{"state":"fixed","versions":["1.17.7"],"available":[{"date":"2026-06-19","kind":"first-observed","version":"1.17.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2303","cwe":"CWE-183","type":"Secondary","source":"cna@mongodb.com"}],"epss":[{"cve":"CVE-2026-2303","date":"2026-10-08","epss":0.00261,"percentile":0.16451}],"risk":0.152685,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-2303","https://jira.mongodb.org/browse/GODRIVER-3770"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cp6g-7hqx-qxhp","description":"mongo-go-driver has Heap Out-of-Bounds Read in GSSAPI Error Handling"},"relatedVulnerabilities":[{"id":"CVE-2026-2303","cvss":[{"type":"Secondary","source":"cna@mongodb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@mongodb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2303","cwe":"CWE-183","type":"Secondary","source":"cna@mongodb.com"}],"epss":[{"cve":"CVE-2026-2303","date":"2026-10-08","epss":0.00261,"percentile":0.16451}],"urls":["https://jira.mongodb.org/browse/GODRIVER-3770"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2303","description":"The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.1485,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19499"},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"risk":0.1485,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19499"},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-08","epss":0.00297,"percentile":0.20503}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"fda25cbf86654709","cpes":["cpe:2.3:a:grafana:agent:v0.23.1-0.20260325080931-372611b64f2c\\+dirty:*:*:*:*:*:*:*"],"name":"github.com/grafana/agent","purl":"pkg:golang/github.com/grafana/agent@v0.23.1-0.20260325080931-372611b64f2c%2Bdirty","type":"go-module","version":"v0.23.1-0.20260325080931-372611b64f2c+dirty","language":"go","licenses":[],"metadata":{"mainModule":"github.com/grafana/agent","architecture":"amd64","goBuildSettings":[{"key":"-buildmode","value":"exe"},{"key":"-compiler","value":"gc"},{"key":"-ldflags","value":"-s -w -X github.com/grafana/agent/internal/build.Branch=main -X github.com/grafana/agent/internal/build.Version=main -X github.com/grafana/agent/internal/build.Revision=372611b64 -X github.com/grafana/agent/internal/build.BuildUser=root@buildkitsandbox -X github.com/grafana/agent/internal/build.BuildDate=2026-03-25T08:14:57Z"},{"key":"-tags","value":"netgo,builtinassets,promtail_journal_enabled"},{"key":"CGO_ENABLED","value":"1"},{"key":"CGO_CFLAGS","value":""},{"key":"CGO_CPPFLAGS","value":""},{"key":"CGO_CXXFLAGS","value":""},{"key":"CGO_LDFLAGS","value":""},{"key":"GOARCH","value":"amd64"},{"key":"GOOS","value":"linux"},{"key":"GOAMD64","value":"v1"},{"key":"vcs","value":"git"},{"key":"vcs.revision","value":"372611b64f2cace1b684c43f6cf0b265b07dbee1"},{"key":"vcs.time","value":"2026-03-25T08:09:31Z"},{"key":"vcs.modified","value":"true"}],"goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.43.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m5gv-m5f9-wgv4","versionConstraint":"<0.43.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/grafana/agent","version":"v0.23.1-0.20260325080931-372611b64f2c+dirty"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-m5gv-m5f9-wgv4","fix":{"state":"fixed","versions":["0.43.3"],"available":[{"date":"2024-10-02","kind":"first-observed","version":"0.43.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U","metrics":{"baseScore":4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-8996","cwe":"CWE-428","type":"Secondary","source":"security@grafana.com"},{"cve":"CVE-2024-8996","cwe":"CWE-428","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-8996","date":"2026-10-08","epss":0.00264,"percentile":0.1683}],"risk":0.14058,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-8996","https://github.com/grafana/agent/releases/tag/v0.43.2","https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996","https://grafana.com/security/security-advisories/cve-2024-8996","https://github.com/grafana/agent/releases/tag/v0.43.3","https://github.com/grafana/agent/commit/91bab2c05906938d3f8e1e3c61a863f037985299","https://pkg.go.dev/vuln/GO-2024-3170"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m5gv-m5f9-wgv4","description":"Grafana Agent (Flow mode) on Windows has Unquoted Search Path or Element vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-8996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security@grafana.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-8996","cwe":"CWE-428","type":"Secondary","source":"security@grafana.com"},{"cve":"CVE-2024-8996","cwe":"CWE-428","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-8996","date":"2026-10-08","epss":0.00264,"percentile":0.1683}],"urls":["https://github.com/grafana/agent/releases/tag/v0.43.3","https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996/","https://grafana.com/security/security-advisories/cve-2024-8996/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-8996","description":"Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM\nThis issue affects Agent Flow: before 0.43.2"}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"18ce0375cc5bec3f","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/ubuntu/libncursesw6@6.4%2B20240113-1ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"< 6.4+20240113-1ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.1"],"available":[{"date":"2026-03-19","kind":"advisory","version":"6.4+20240113-1ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.1341,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69720"},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"9d92803c72cb7a13","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/ubuntu/libtinfo6@6.4%2B20240113-1ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"< 6.4+20240113-1ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.1"],"available":[{"date":"2026-03-19","kind":"advisory","version":"6.4+20240113-1ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.1341,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69720"},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"9ce712b33a96bea6","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.4%2B20240113-1ubuntu2?arch=all&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"< 6.4+20240113-1ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.1"],"available":[{"date":"2026-03-19","kind":"advisory","version":"6.4+20240113-1ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.1341,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69720"},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"e94839bb1b1744f0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.4%2B20240113-1ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"< 6.4+20240113-1ubuntu2.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.1"],"available":[{"date":"2026-03-19","kind":"advisory","version":"6.4+20240113-1ubuntu2.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"risk":0.1341,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-69720"},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-08","epss":0.00447,"percentile":0.36881}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"8f4cf9baab26d4f0","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.5?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"c322cb2c91836caa","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.5?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"d04a485a523784c8","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.5?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"9aa31bc48b99a584","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.5:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.5?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"a6bbe16f49176f0a","cpes":["cpe:2.3:a:otel:sdk:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/sdk","purl":"pkg:golang/go.opentelemetry.io/otel/sdk@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:YMPPDNymmQN3ZgczicBY3B6sf9n62Dlj9pWD3ucgoDw=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.40.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9h8m-3fm2-qjrq","versionConstraint":">=1.21.0,<1.40.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/sdk","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-9h8m-3fm2-qjrq","fix":{"state":"fixed","versions":["1.40.0"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"1.40.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24051","cwe":"CWE-426","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24051","date":"2026-10-08","epss":0.00179,"percentile":0.06805}],"risk":0.12977499999999997,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-9h8m-3fm2-qjrq","https://github.com/open-telemetry/opentelemetry-go/commit/d45961bcda453fcbdb6469c22d6e88a1f9970a53","https://nvd.nist.gov/vuln/detail/CVE-2026-24051","https://pkg.go.dev/vuln/GO-2026-4394"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9h8m-3fm2-qjrq","description":"OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking"},"relatedVulnerabilities":[{"id":"CVE-2026-24051","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24051","cwe":"CWE-426","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-24051","date":"2026-10-08","epss":0.00179,"percentile":0.06805}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/d45961bcda453fcbdb6469c22d6e88a1f9970a53","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-9h8m-3fm2-qjrq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24051","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0."}]},{"artifact":{"id":"712f8799b6e88601","cpes":["cpe:2.3:a:jackc:pgx\\/v4:v4.18.2:*:*:*:*:*:*:*"],"name":"github.com/jackc/pgx/v4","purl":"pkg:golang/github.com/jackc/pgx/v4@v4.18.2","type":"go-module","version":"v4.18.2","language":"go","licenses":[],"metadata":{"h1Digest":"h1:xVpYkNR5pk5bMCZGfClbO962UIqVABcAGt7ha1s/FeU=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j88v-2chj-qfwx","versionConstraint":"<=4.18.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/jackc/pgx/v4","version":"v4.18.2"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-j88v-2chj-qfwx","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41889","cwe":"CWE-89","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41889","date":"2026-10-08","epss":0.00488,"percentile":0.40084}],"risk":0.12932,"urls":["https://github.com/jackc/pgx/security/advisories/GHSA-j88v-2chj-qfwx","https://github.com/jackc/pgx/commit/60644f84918a8af66d14a4b0d865d4edafd955da","https://github.com/jackc/pgx/releases/tag/v5.9.2","https://nvd.nist.gov/vuln/detail/CVE-2026-41889"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j88v-2chj-qfwx","description":"pgx: SQL Injection via placeholder confusion with dollar quoted string literals"},"relatedVulnerabilities":[{"id":"CVE-2026-41889","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41889","cwe":"CWE-89","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41889","date":"2026-10-08","epss":0.00488,"percentile":0.40084}],"urls":["https://github.com/jackc/pgx/commit/60644f84918a8af66d14a4b0d865d4edafd955da","https://github.com/jackc/pgx/releases/tag/v5.9.2","https://github.com/jackc/pgx/security/advisories/GHSA-j88v-2chj-qfwx"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41889","description":"pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2."}]},{"artifact":{"id":"063550efa23293f6","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.2:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.2","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"< 5.38.2-3.2ubuntu0.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.6"],"available":[{"date":"2026-09-16","kind":"advisory","version":"5.38.2-3.2ubuntu0.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"risk":0.128,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15534"},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-08","epss":0.00256,"percentile":0.15832}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42767","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42767","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42767"},"relatedVulnerabilities":[{"id":"CVE-2026-42767","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42767","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42767","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42767"},"relatedVulnerabilities":[{"id":"CVE-2026-42767","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.18.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3xc5-wrhm-f963","versionConstraint":"<=5.17.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-3xc5-wrhm-f963","fix":{"state":"fixed","versions":["5.18.0"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"5.18.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41506","cwe":"CWE-522","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41506","date":"2026-10-08","epss":0.00259,"percentile":0.16118}],"risk":0.125615,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963","https://nvd.nist.gov/vuln/detail/CVE-2026-41506","https://github.com/go-git/go-git/releases/tag/v5.18.0","https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.2"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3xc5-wrhm-f963","description":"go-git: Credential leak via cross-host redirect in smart HTTP transport"},"relatedVulnerabilities":[{"id":"CVE-2026-41506","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","metrics":{"baseScore":7.4,"impactScore":4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41506","cwe":"CWE-522","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41506","date":"2026-10-08","epss":0.00259,"percentile":0.16118}],"urls":["https://github.com/go-git/go-git/releases/tag/v5.18.0","https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.2","https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41506","description":"go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2."}]},{"artifact":{"id":"6860f54cb4c4abbc","cpes":["cpe:2.3:a:docker:docker:v25.0.6\\+incompatible:*:*:*:*:*:*:*"],"name":"github.com/docker/docker","purl":"pkg:golang/github.com/docker/docker@v25.0.6%2Bincompatible","type":"go-module","version":"v25.0.6+incompatible","language":"go","licenses":[],"metadata":{"h1Digest":"h1:5cPwbwriIcsua2REJe8HqQV+6WlWc1byg2QSXzBxBGg=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4887","versionConstraint":"none (unknown)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/docker/docker","version":"v25.0.6+incompatible"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4887","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34040","cwe":"CWE-288","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34040","date":"2026-10-08","epss":0.00163,"percentile":0.05035}],"risk":0.12469499999999999,"urls":["https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38","https://docs.docker.com/engine/extend/plugins_authorization","https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2","description":"Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker"},"relatedVulnerabilities":[{"id":"CVE-2026-34040","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":6.1,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34040","cwe":"CWE-288","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34040","date":"2026-10-08","epss":0.00163,"percentile":0.05035}],"urls":["https://github.com/moby/moby/releases/tag/docker-v29.3.1","https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34040","description":"Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1."},{"id":"GHSA-x744-4wpc-v9h2","cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":6.1,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34040","cwe":"CWE-288","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34040","date":"2026-10-08","epss":0.00163,"percentile":0.05035}],"urls":["https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq","https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2","https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38","https://docs.docker.com/engine/extend/plugins_authorization","https://nvd.nist.gov/vuln/detail/CVE-2026-34040","https://github.com/moby/moby/releases/tag/docker-v29.3.1"],"severity":"High","namespace":"github:language:go","dataSource":"https://github.com/advisories/GHSA-x744-4wpc-v9h2","description":"Moby has AuthZ plugin bypass when provided oversized request bodies"}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5030","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5030","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27136","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27136","date":"2026-10-08","epss":0.00223,"percentile":0.11872}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781685"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79575","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-27136","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27136","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27136","date":"2026-10-08","epss":0.00223,"percentile":0.11872}],"urls":["https://go.dev/cl/781685","https://go.dev/issue/79575","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5030"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27136","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5027","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5027","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42502","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42502","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781701"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79572","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-42502","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42502","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-42502","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"urls":["https://go.dev/cl/781701","https://go.dev/issue/79572","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5027"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42502","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5029","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5029","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-05-22","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25681","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25681","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"risk":0.12376500000000001,"urls":["https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://go.dev/cl/781703"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79574","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."},"relatedVulnerabilities":[{"id":"CVE-2026-25681","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25681","cwe":"CWE-1021","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-25681","date":"2026-10-08","epss":0.00223,"percentile":0.11871}],"urls":["https://go.dev/cl/781703","https://go.dev/issue/79574","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5029"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25681","description":"Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7017","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7017","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7017"},"relatedVulnerabilities":[{"id":"CVE-2026-7017","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7017","cwe":"CWE-522","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-7017","date":"2026-10-08","epss":0.00247,"percentile":0.14674}],"urls":["https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/8f32ca89e21c3ad0422adc698fa6ad17a193f55f.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/e7a03aedf2395158f2b0d3bad2df943349227bb3.patch","https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36","https://metacpan.org/release/HAARG/HTTP-Tiny-0.095-TRIAL/changes","http://www.openwall.com/lists/oss-security/2026/07/07/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7017","description":"HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets.\n\nWhen the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header and `_prepare_headers_and_cb` re-merges the caller's `headers` argument into the new request, without checking whether the redirect target shares an origin with the original URL. Caller-supplied `Authorization`, `Cookie` and `Proxy-Authorization` headers are therefore re-sent to whatever host the redirect names, across scheme, host or port boundaries, and including `https` to `http` downgrades that expose them in plaintext on the wire.\n\nThe HTTP::Tiny POD note that \"Authorization headers will not be included in a redirected request\" applied only to the URL-userinfo Basic-auth path, not to headers passed explicitly by the caller."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"6860f54cb4c4abbc","cpes":["cpe:2.3:a:docker:docker:v25.0.6\\+incompatible:*:*:*:*:*:*:*"],"name":"github.com/docker/docker","purl":"pkg:golang/github.com/docker/docker@v25.0.6%2Bincompatible","type":"go-module","version":"v25.0.6+incompatible","language":"go","licenses":[],"metadata":{"h1Digest":"h1:5cPwbwriIcsua2REJe8HqQV+6WlWc1byg2QSXzBxBGg=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x86f-5xw2-fm2r","versionConstraint":"<=28.5.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/docker/docker","version":"v25.0.6+incompatible"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-x86f-5xw2-fm2r","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","metrics":{"baseScore":7.2,"impactScore":5.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41567","cwe":"CWE-427","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41567","cwe":"CWE-427","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41567","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.12127500000000001,"urls":["https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r","https://nvd.nist.gov/vuln/detail/CVE-2026-41567"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x86f-5xw2-fm2r","description":"Docker: `PUT /containers/{id}/archive` executes container binary on the host"},"relatedVulnerabilities":[{"id":"CVE-2026-41567","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":6.1,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","metrics":{"baseScore":7.2,"impactScore":5.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41567","cwe":"CWE-427","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41567","cwe":"CWE-427","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41567","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/security/cve/CVE-2026-41567","https://bugzilla.redhat.com/show_bug.cgi?id=2485356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41567","description":"Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images"}]},{"artifact":{"id":"7253ad92559632bb","cpes":["cpe:2.3:a:golang:text:v0.31.0:*:*:*:*:*:*:*"],"name":"golang.org/x/text","purl":"pkg:golang/golang.org/x/text@v0.31.0","type":"go-module","version":"v0.31.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:aC8ghyu4JhP8VojJ2lEHBnochRno1sgL6nEi9WGFGMM=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.41.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6629","versionConstraint":"<0.41.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/text","version":"v0.31.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6629","fix":{"state":"fixed","versions":["0.41.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.41.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"risk":0.11624999999999999,"urls":["https://go.dev/issue/80112"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/793360","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."},"relatedVulnerabilities":[{"id":"CVE-2026-56851","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56851","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56851","date":"2026-10-08","epss":0.00155,"percentile":0.04088}],"urls":["https://go.dev/cl/793360","https://go.dev/issue/80112","https://pkg.go.dev/vuln/GO-2026-6629"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56851","description":"The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.1161,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75806"},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.1161,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75806"},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.19.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-389r-gv7p-r3rp","versionConstraint":"<5.19.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-389r-gv7p-r3rp","fix":{"state":"fixed","versions":["5.19.0"],"available":[{"date":"2026-05-11","kind":"first-observed","version":"5.19.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45022","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45022","cwe":"CWE-345","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45022","date":"2026-10-08","epss":0.00159,"percentile":0.0444}],"risk":0.11527499999999999,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp","https://nvd.nist.gov/vuln/detail/CVE-2026-45022"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-389r-gv7p-r3rp","description":"go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git"},"relatedVulnerabilities":[{"id":"CVE-2026-45022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45022","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45022","cwe":"CWE-345","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45022","date":"2026-10-08","epss":0.00159,"percentile":0.0444}],"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45022","description":"go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose values differently from how Git itself would interpret or reject the same object. Additionally, go-git’s commit signing and verification logic operates over commit data reconstructed from go-git’s parsed representation rather than the original raw object bytes. As a result, go-git may sign or verify a commit payload that is not byte-for-byte equivalent to the object stored in the repository. This can cause a signature to appear valid for a commit whose displayed or effective metadata differs from the object that was intended to be signed. This vulnerability is fixed in 5.19.0 and 6.0.0-alpha.3."}]},{"artifact":{"id":"c988386b52899b07","cpes":["cpe:2.3:a:cloudflare:circl:v1.6.1:*:*:*:*:go:*:*"],"name":"github.com/cloudflare/circl","purl":"pkg:golang/github.com/cloudflare/circl@v1.6.1","type":"go-module","version":"v1.6.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:zqIqSPIndyBh1bjLVVDHMPpVKqp8Su/V+6MeDzzQBQ0=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.6.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q9hv-hpm4-hj6x","versionConstraint":"<1.6.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/cloudflare/circl","version":"v1.6.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-q9hv-hpm4-hj6x","fix":{"state":"fixed","versions":["1.6.3"],"available":[{"date":"2026-03-04","kind":"first-observed","version":"1.6.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/U:Amber","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1229","cwe":"CWE-682","type":"Secondary","source":"cna@cloudflare.com"}],"epss":[{"cve":"CVE-2026-1229","date":"2026-10-08","epss":0.00389,"percentile":0.30912}],"risk":0.11475499999999998,"urls":["https://github.com/cloudflare/circl/security/advisories/GHSA-q9hv-hpm4-hj6x","https://nvd.nist.gov/vuln/detail/CVE-2026-1229","https://github.com/cloudflare/circl/pull/583","https://github.com/cloudflare/circl/releases/tag/v1.6.3"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q9hv-hpm4-hj6x","description":"CIRCL has an incorrect calculation in secp384r1 CombinedMult"},"relatedVulnerabilities":[{"id":"CVE-2026-1229","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@cloudflare.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1229","cwe":"CWE-682","type":"Secondary","source":"cna@cloudflare.com"}],"epss":[{"cve":"CVE-2026-1229","date":"2026-10-08","epss":0.00389,"percentile":0.30912}],"urls":["https://github.com/cloudflare/circl"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1229","description":"The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.\nECDH and ECDSA signing relying on this curve are not affected.\n\nThe bug was fixed in  v1.6.3 https://github.com/cloudflare/circl/releases/tag/v1.6.3 ."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.19.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m7cr-m3pv-hgrp","versionConstraint":"<=5.19.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-m7cr-m3pv-hgrp","fix":{"state":"fixed","versions":["5.19.1"],"available":[{"date":"2026-05-19","kind":"first-observed","version":"5.19.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45570","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45570","date":"2026-10-08","epss":0.00427,"percentile":0.34965}],"risk":0.113155,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp","https://nvd.nist.gov/vuln/detail/CVE-2026-45570"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m7cr-m3pv-hgrp","description":"go-git: Improper single-quote escaping in go-git SSH transport"},"relatedVulnerabilities":[{"id":"CVE-2026-45570","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":9.6,"impactScore":6.1,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45570","cwe":"CWE-116","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45570","date":"2026-10-08","epss":0.00427,"percentile":0.34965}],"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45570","description":"go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as additional shell tokens. This vulnerability is fixed in 5.19.1 and 6.0.0-alpha.4."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11299999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19542"},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"risk":0.11299999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19542"},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-08","epss":0.00226,"percentile":0.1218}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6791"},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"risk":0.11,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6791"},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-08","epss":0.0022,"percentile":0.11377}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57432","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57432","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"risk":0.1055,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57432"},"relatedVulnerabilities":[{"id":"CVE-2026-57432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57432","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-57432","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-57432","date":"2026-10-08","epss":0.00211,"percentile":0.10407}],"urls":["https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e.patch","https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55.patch","http://www.openwall.com/lists/oss-security/2026/07/13/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57432","description":"Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.\n\nS_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.\n\nA template derived from untrusted input can read heap memory past the buffer and return it to the caller."}]},{"artifact":{"id":"0ff6c45a645ef14b","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/ubuntu/libp11-kit0@0.25.3-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=p11-kit","type":"deb","version":"0.25.3-4ubuntu2.1","language":"","licenses":["Apache-2.0","BSD-3-clause","FSFAP","FSFULLR","GPL-2+","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","X11","customFSFUL","customFSFULLRWD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.25.3-4ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"< 0.25.3-4ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"p11-kit","version":"0.25.3-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13757","fix":{"state":"fixed","versions":["0.25.3-4ubuntu2.2"],"available":[{"date":"2026-08-27","kind":"advisory","version":"0.25.3-4ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"risk":0.101,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13757"},"relatedVulnerabilities":[{"id":"CVE-2026-13757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-08","epss":0.00202,"percentile":0.09262}],"urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."}]},{"artifact":{"id":"c8e83c9ce9a5ba5b","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.3-1.1ubuntu3.5:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/ubuntu/libgnutls30t64@3.8.3-1.1ubuntu3.5?arch=amd64&distro=ubuntu-24.04&upstream=gnutls28","type":"deb","version":"3.8.3-1.1ubuntu3.5","language":"","licenses":["sha256:51da5214308b87d6a0a2fbcaea1f7dbd15510be733e5921d9548ff6b88d84dd8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.8.3-1.1ubuntu3.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42014","versionConstraint":"< 3.8.3-1.1ubuntu3.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42014","fix":{"state":"fixed","versions":["3.8.3-1.1ubuntu3.6"],"available":[{"date":"2026-05-20","kind":"advisory","version":"3.8.3-1.1ubuntu3.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42014","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42014","date":"2026-10-08","epss":0.002,"percentile":0.09032}],"risk":0.1,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42014"},"relatedVulnerabilities":[{"id":"CVE-2026-42014","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.6,"impactScore":4.8,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42014","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42014","date":"2026-10-08","epss":0.002,"percentile":0.09032}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42014","https://bugzilla.redhat.com/show_bug.cgi?id=2467451","https://gitlab.com/gnutls/gnutls/-/issues/1766","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42014","description":"A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path."}]},{"artifact":{"id":"8e80bcb06e477c56","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlpmetric\\/otlpmetrichttp:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:mM8nKi6/iFQ0iqst80wDHU2ge198Ye/TfN0WBS5U24Y=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.43.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w8rr-5gcm-pp58","versionConstraint":"<1.43.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w8rr-5gcm-pp58","fix":{"state":"fixed","versions":["1.43.0"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"1.43.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39882","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39882","date":"2026-10-08","epss":0.0019,"percentile":0.07935}],"risk":0.09784999999999999,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w8rr-5gcm-pp58","http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0","https://nvd.nist.gov/vuln/detail/CVE-2026-39882","https://github.com/open-telemetry/opentelemetry-go/pull/8108"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w8rr-5gcm-pp58","description":"opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies"},"relatedVulnerabilities":[{"id":"CVE-2026-39882","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39882","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39882","date":"2026-10-08","epss":0.0019,"percentile":0.07935}],"urls":["https://github.com/open-telemetry/opentelemetry-go/pull/8108","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w8rr-5gcm-pp58"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39882","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0."}]},{"artifact":{"id":"02ffa4a48a219768","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace\\/otlptracehttp:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Xw8U6u2f8DK2XAkGRFV7BBLENgnTGX9i4rQRxJf+/vs=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.43.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w8rr-5gcm-pp58","versionConstraint":"<1.43.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w8rr-5gcm-pp58","fix":{"state":"fixed","versions":["1.43.0"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"1.43.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39882","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39882","date":"2026-10-08","epss":0.0019,"percentile":0.07935}],"risk":0.09784999999999999,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w8rr-5gcm-pp58","http://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0","https://nvd.nist.gov/vuln/detail/CVE-2026-39882","https://github.com/open-telemetry/opentelemetry-go/pull/8108"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w8rr-5gcm-pp58","description":"opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies"},"relatedVulnerabilities":[{"id":"CVE-2026-39882","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39882","cwe":"CWE-789","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-39882","date":"2026-10-08","epss":0.0019,"percentile":0.07935}],"urls":["https://github.com/open-telemetry/opentelemetry-go/pull/8108","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w8rr-5gcm-pp58"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39882","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-31789","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"risk":0.09749999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-31789"},"relatedVulnerabilities":[{"id":"CVE-2026-31789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-31789","versionConstraint":"< 3.0.13-0ubuntu3.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.9"],"available":[{"date":"2026-04-08","kind":"advisory","version":"3.0.13-0ubuntu3.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"risk":0.09749999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-31789"},"relatedVulnerabilities":[{"id":"CVE-2026-31789","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"adc014ee755a970f","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.10.3-2build1:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/ubuntu/libgcrypt20@1.10.3-2build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.10.3-2build1","language":"","licenses":["sha256:40162167dff80843a4b24aa8d0a4ffc50be5338d004ebe38f86ae3397ba9de3e"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.10.3-2ubuntu0.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41989","versionConstraint":"< 1.10.3-2ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libgcrypt20","version":"1.10.3-2build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41989","fix":{"state":"fixed","versions":["1.10.3-2ubuntu0.1"],"available":[{"date":"2026-05-27","kind":"advisory","version":"1.10.3-2ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-41989","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41989","date":"2026-10-08","epss":0.00192,"percentile":0.08104}],"risk":0.096,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41989"},"relatedVulnerabilities":[{"id":"CVE-2026-41989","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.2,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41989","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-41989","date":"2026-10-08","epss":0.00192,"percentile":0.08104}],"urls":["https://dev.gnupg.org/T8211","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html","https://www.openwall.com/lists/oss-security/2026/04/21/1","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41989","description":"Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4869","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4869","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"risk":0.09555000000000001,"urls":["https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763766","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."},"relatedVulnerabilities":[{"id":"CVE-2026-32288","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"urls":["https://go.dev/cl/763766","https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4869"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32288","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"a6bbe16f49176f0a","cpes":["cpe:2.3:a:otel:sdk:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/sdk","purl":"pkg:golang/go.opentelemetry.io/otel/sdk@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:YMPPDNymmQN3ZgczicBY3B6sf9n62Dlj9pWD3ucgoDw=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.33.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p9f8-wvj8-2fg8","versionConstraint":">=1.10.0,<1.33.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/sdk","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-p9f8-wvj8-2fg8","fix":{"state":"fixed","versions":["1.33.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"1.33.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81869","cwe":"CWE-176","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81869","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81869","date":"2026-10-08","epss":0.0018,"percentile":0.06928}],"risk":0.0909,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-p9f8-wvj8-2fg8","https://nvd.nist.gov/vuln/detail/CVE-2026-81869","https://github.com/open-telemetry/opentelemetry-go/issues/5996","https://github.com/open-telemetry/opentelemetry-go/pull/5997","https://github.com/open-telemetry/opentelemetry-go/commit/e016a78c9f5b24a1c2beeaad47686c2f2213f49a","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.33.0"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p9f8-wvj8-2fg8","description":"OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation"},"relatedVulnerabilities":[{"id":"CVE-2026-81869","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81869","cwe":"CWE-176","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81869","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81869","date":"2026-10-08","epss":0.0018,"percentile":0.06928}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/e016a78c9f5b24a1c2beeaad47686c2f2213f49a","https://github.com/open-telemetry/opentelemetry-go/issues/5996","https://github.com/open-telemetry/opentelemetry-go/pull/5997","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.33.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-p9f8-wvj8-2fg8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81869","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing the valid Unicode replacement character U+FFFD. safeTruncateValidUTF8 treats the valid replacement rune as invalid UTF-8 and returns the original input, while strings.ToValidUTF8 leaves that valid rune unchanged, so a second safeTruncate attempt can also return the oversized value. An attacker who controls span attribute content can retain values longer than the configured limit, increasing per-span memory use and weakening denial-of-service protection in the instrumented process. This issue is fixed in version 1.33.0."}]},{"artifact":{"id":"f220b53ee9e82286","cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.2-1build1.1:*:*:*:*:*:*:*"],"name":"libattr1","purl":"pkg:deb/ubuntu/libattr1@1%3A2.5.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=attr","type":"deb","version":"1:2.5.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libattr1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libattr1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"attr"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:2.5.2-1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"< 1:2.5.2-1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"attr","version":"1:2.5.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54371","fix":{"state":"fixed","versions":["1:2.5.2-1ubuntu0.1"],"available":[{"date":"2026-08-31","kind":"advisory","version":"1:2.5.2-1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54371"},"relatedVulnerabilities":[{"id":"CVE-2026-54371","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-08","epss":0.00179,"percentile":0.06854}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/errata/RHSA-2026:56133","https://access.redhat.com/errata/RHSA-2026:59380","https://access.redhat.com/errata/RHSA-2026:60226","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."}]},{"artifact":{"id":"c523498c8ece7464","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.4:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.4?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.4","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"063550efa23293f6","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.2:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.2","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"9.4-3ubuntu6.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5278","versionConstraint":"< 9.4-3ubuntu6.3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-5278","fix":{"state":"fixed","versions":["9.4-3ubuntu6.3"],"available":[{"date":"2026-08-31","kind":"advisory","version":"9.4-3ubuntu6.3"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5278","date":"2026-10-08","epss":0.00288,"percentile":0.19615}],"risk":0.0864,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-5278"},"relatedVulnerabilities":[{"id":"CVE-2025-5278","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5278","cwe":"CWE-121","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5278","date":"2026-10-08","epss":0.00288,"percentile":0.19615}],"urls":["https://access.redhat.com/errata/RHSA-2026:28911","https://access.redhat.com/errata/RHSA-2026:33124","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:33612","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:69964","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2025-5278","https://bugzilla.redhat.com/show_bug.cgi?id=2368764","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507","http://www.openwall.com/lists/oss-security/2025/05/27/2","http://www.openwall.com/lists/oss-security/2025/05/29/1","http://www.openwall.com/lists/oss-security/2025/05/29/2","https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14","https://security-tracker.debian.org/tracker/CVE-2025-5278"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5278","description":"A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data."}]},{"artifact":{"id":"928e44e5e603a57e","cpes":["cpe:2.3:a:opencontainers:runc:v1.1.14:*:*:*:*:*:*:*"],"name":"github.com/opencontainers/runc","purl":"pkg:golang/github.com/opencontainers/runc@v1.1.14","type":"go-module","version":"v1.1.14","language":"go","licenses":[],"metadata":{"h1Digest":"h1:rgSuzbmgz5DUJjeSnw337TxDbRuqjs6iqQck/2weR6w=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xjvp-4fhw-gc47","versionConstraint":"<=1.3.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/opencontainers/runc","version":"v1.1.14"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-xjvp-4fhw-gc47","fix":{"state":"fixed","versions":["1.3.6"],"available":[{"date":"2026-06-23","kind":"first-observed","version":"1.3.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41579","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41579","date":"2026-10-08","epss":0.00186,"percentile":0.07536}],"risk":0.084165,"urls":["https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xjvp-4fhw-gc47","description":"runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations"},"relatedVulnerabilities":[{"id":"CVE-2026-41579","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41579","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41579","date":"2026-10-08","epss":0.00186,"percentile":0.07536}],"urls":["https://github.com/opencontainers/runc/commit/864db8042dbb","https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41579","description":"runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a filepath.Join string which allow an image with /dev as a symlink to trick runc into deleting files called ptmx on the host or creating a hardcoded set of symlinks with specific names and targets in an arbitrary pre-existing host directory. This issue is not exploitable under Docker, because Docker creates a top-level read-only layer that masks any malicious /dev symlink present in the container image — unlike some other Linux container tooling, whose higher-level runtimes built on runc remain exposed to exploitation via a malicious image. This issue has been fixed in versions 1.3.6, 1.4.3 and 1.5.0."}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13595"},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13595"},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13595"},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13595"},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13595"},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13595"},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13595","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13595","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13595"},"relatedVulnerabilities":[{"id":"CVE-2026-13595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13595","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13595","date":"2026-10-08","epss":0.00168,"percentile":0.05619}],"urls":["https://access.redhat.com/errata/RHSA-2026:26573","https://access.redhat.com/security/cve/CVE-2026-13595","https://bugzilla.redhat.com/show_bug.cgi?id=2494101","https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13595","description":"A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.16.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-37cx-329c-33x3","versionConstraint":"<=5.16.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-37cx-329c-33x3","fix":{"state":"fixed","versions":["5.16.5"],"available":[{"date":"2026-02-10","kind":"first-observed","version":"5.16.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25934","cwe":"CWE-354","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25934","date":"2026-10-08","epss":0.00176,"percentile":0.06451}],"risk":0.08184,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-37cx-329c-33x3","https://github.com/go-git/go-git/releases/tag/v5.16.5","https://nvd.nist.gov/vuln/detail/CVE-2026-25934"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-37cx-329c-33x3","description":"go-git improperly verifies data integrity values for .idx and .pack files"},"relatedVulnerabilities":[{"id":"CVE-2026-25934","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25934","cwe":"CWE-354","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25934","date":"2026-10-08","epss":0.00176,"percentile":0.06451}],"urls":["https://github.com/go-git/go-git/releases/tag/v5.16.5","https://github.com/go-git/go-git/security/advisories/GHSA-37cx-329c-33x3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25934","description":"go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified. This resulted in go-git potentially consuming corrupted files, which would likely result in unexpected errors such as object not found. For context, clients fetch packfiles from upstream Git servers. Those files contain a checksum of their contents, so that clients can perform integrity checks before consuming it. The pack indexes (.idx) are generated locally by go-git, or the git cli, when new .pack files are received and processed. The integrity checks for both files were not being verified correctly. This vulnerability is fixed in 5.16.5."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.08009999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35189"},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.08009999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-35189"},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"1855f796e9291224","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"255.4-1ubuntu8.17"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"< 255.4-1ubuntu8.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"fixed","versions":["255.4-1ubuntu8.17"],"available":[{"date":"2026-08-10","kind":"advisory","version":"255.4-1ubuntu8.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.0795,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15059"},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"e3b5cb8c2c8c33bf","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"255.4-1ubuntu8.17"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"< 255.4-1ubuntu8.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"fixed","versions":["255.4-1ubuntu8.17"],"available":[{"date":"2026-08-10","kind":"advisory","version":"255.4-1ubuntu8.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"risk":0.0795,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15059"},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-08","epss":0.00159,"percentile":0.04463}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.0789,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54872"},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.0789,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54872"},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42770","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42770","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004}],"risk":0.0774,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42770"},"relatedVulnerabilities":[{"id":"CVE-2026-42770","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004}],"urls":["https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02","https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb","https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c","https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2","https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42770","description":"Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42770","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42770","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004}],"risk":0.0774,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42770"},"relatedVulnerabilities":[{"id":"CVE-2026-42770","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42770","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42770","date":"2026-10-08","epss":0.00258,"percentile":0.16004}],"urls":["https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02","https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb","https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c","https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2","https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42770","description":"Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue."}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"0ff6c45a645ef14b","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.3-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/ubuntu/libp11-kit0@0.25.3-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=p11-kit","type":"deb","version":"0.25.3-4ubuntu2.1","language":"","licenses":["Apache-2.0","BSD-3-clause","FSFAP","FSFULLR","GPL-2+","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","X11","customFSFUL","customFSFULLRWD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"fix":{"suggestedVersion":"0.25.3-4ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18938","versionConstraint":"< 0.25.3-4ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"p11-kit","version":"0.25.3-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18938","fix":{"state":"fixed","versions":["0.25.3-4ubuntu2.2"],"available":[{"date":"2026-08-27","kind":"advisory","version":"0.25.3-4ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-08","epss":0.00152,"percentile":0.03827}],"risk":0.076,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18938"},"relatedVulnerabilities":[{"id":"CVE-2026-18938","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-08","epss":0.00152,"percentile":0.03827}],"urls":["https://access.redhat.com/security/cve/CVE-2026-18938","https://bugzilla.redhat.com/show_bug.cgi?id=2478995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.17.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jhf3-xxhw-2wpp","versionConstraint":">=5.0.0,<=5.17.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-jhf3-xxhw-2wpp","fix":{"state":"fixed","versions":["5.17.1"],"available":[{"date":"2026-03-31","kind":"first-observed","version":"5.17.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34165","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34165","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34165","date":"2026-10-08","epss":0.00148,"percentile":0.03458}],"risk":0.074,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-jhf3-xxhw-2wpp","https://github.com/go-git/go-git/releases/tag/v5.17.1","https://nvd.nist.gov/vuln/detail/CVE-2026-34165"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jhf3-xxhw-2wpp","description":"go-git: Maliciously crafted idx file can cause asymmetric memory consumption"},"relatedVulnerabilities":[{"id":"CVE-2026-34165","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34165","cwe":"CWE-191","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-34165","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34165","date":"2026-10-08","epss":0.00148,"percentile":0.03458}],"urls":["https://github.com/go-git/go-git/releases/tag/v5.17.1","https://github.com/go-git/go-git/security/advisories/GHSA-jhf3-xxhw-2wpp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34165","description":"go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric memory consumption, potentially exhausting available memory and resulting in a denial-of-service (DoS) condition. Exploitation requires write access to the local repository's .git directory, it order to create or alter existing .idx files. This issue has been patched in version 5.17.1."}]},{"artifact":{"id":"6860f54cb4c4abbc","cpes":["cpe:2.3:a:docker:docker:v25.0.6\\+incompatible:*:*:*:*:*:*:*"],"name":"github.com/docker/docker","purl":"pkg:golang/github.com/docker/docker@v25.0.6%2Bincompatible","type":"go-module","version":"v25.0.6+incompatible","language":"go","licenses":[],"metadata":{"h1Digest":"h1:5cPwbwriIcsua2REJe8HqQV+6WlWc1byg2QSXzBxBGg=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rg2x-37c3-w2rh","versionConstraint":"<=28.5.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/docker/docker","version":"v25.0.6+incompatible"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-rg2x-37c3-w2rh","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.2,"impactScore":5.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42306","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42306","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42306","date":"2026-10-08","epss":0.001,"percentile":0.00788}],"risk":0.0735,"urls":["https://github.com/moby/moby/security/advisories/GHSA-rg2x-37c3-w2rh","https://nvd.nist.gov/vuln/detail/CVE-2026-42306"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rg2x-37c3-w2rh","description":"Docker: Race condition in docker cp allows bind mount redirection to host path"},"relatedVulnerabilities":[{"id":"CVE-2026-42306","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.2,"impactScore":5.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.2,"impactScore":5.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42306","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42306","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42306","date":"2026-10-08","epss":0.001,"percentile":0.00788}],"urls":["https://github.com/moby/moby/security/advisories/GHSA-rg2x-37c3-w2rh"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42306","description":"Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.07289999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77696"},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77696","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.07289999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77696"},"relatedVulnerabilities":[{"id":"CVE-2026-77696","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"6ef02dd49ce06248","cpes":["cpe:2.3:a:gzip:gzip:1.12-1ubuntu3.1:*:*:*:*:*:*:*"],"name":"gzip","purl":"pkg:deb/ubuntu/gzip@1.12-1ubuntu3.1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.12-1ubuntu3.1","language":"","licenses":["FSF-manpages","GFDL-1.3+-no-invariant","GFDL-3","GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gzip/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/gzip/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gzip.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.list"},{"path":"/var/lib/dpkg/info/gzip.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.postinst"},{"path":"/var/lib/dpkg/info/gzip.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gzip.preinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.12-1ubuntu3.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41991","versionConstraint":"< 1.12-1ubuntu3.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gzip","version":"1.12-1ubuntu3.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41991","fix":{"state":"fixed","versions":["1.12-1ubuntu3.2"],"available":[{"date":"2026-07-06","kind":"advisory","version":"1.12-1ubuntu3.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41991","date":"2026-10-08","epss":0.00142,"percentile":0.02987}],"risk":0.07100000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41991"},"relatedVulnerabilities":[{"id":"CVE-2026-41991","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41991","cwe":"CWE-377","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-41991","date":"2026-10-08","epss":0.00142,"percentile":0.02987}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-41991/","https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269","https://www.gnu.org/software/gzip/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41991","description":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269"}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45446","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45446","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414}],"risk":0.0708,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45446"},"relatedVulnerabilities":[{"id":"CVE-2026-45446","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414}],"urls":["https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc","https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3","https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85","https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598","https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45446","description":"Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45446","versionConstraint":"< 3.0.13-0ubuntu3.11 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45446","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.11"],"available":[{"date":"2026-06-09","kind":"advisory","version":"3.0.13-0ubuntu3.11"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414}],"risk":0.0708,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45446"},"relatedVulnerabilities":[{"id":"CVE-2026-45446","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45446","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45446","date":"2026-10-08","epss":0.00236,"percentile":0.13414}],"urls":["https://github.com/openssl/openssl/commit/25b32cd9d41d2bc01b6abc425bb4baf2c2236fdc","https://github.com/openssl/openssl/commit/71e2a5d263518cf5866043bd60ee4994d59e53a3","https://github.com/openssl/openssl/commit/7fe3f33a3b3a4c487aa4dcdbc87057f66ffd2b85","https://github.com/openssl/openssl/commit/daca0f48e4a69a2892a62262bad59e62a8a76598","https://github.com/openssl/openssl/commit/eec5e9bf0d867333b8495e456f5235d225798a68","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45446","description":"Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV\n(RFC 8452) mishandle the authentication of AAD (Additional Authenticated\nData) with an empty ciphertext allowing a forgery of such messages.\n\nImpact summary: An attacker can forge empty messages with arbitrary AAD\nto the victim's application using these ciphers.\n\nAES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD\nmodes: they accept a key, nonce, optional AAD (bytes that are authenticated\nbut not encrypted), and plaintext, and produces ciphertext plus a 16-byte\ntag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only\nif the tag is verified succesfully.\n\nIn OpenSSL's provider implementation of these ciphers, the expected tag is\ncomputed only when decryption function is invoked with non-empty data.\nIf the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without\ninvocation of the ciphertext update, which can happen when the received\nciphertext length is zero, the tag is never recalculated and still holds its\nall-zeros value.\n\nWhen AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty\nciphertext, and all-zeros tag passes authentication under any key they do not\nknow, single-shot. When AES-SIV is used, for mounting the attack it's\nnecessary for the application to reuse the decryption context without\nresetting the key.\n\nAES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since\nOpenSSL 3.2.\n\nNo protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support\neither AES-GCM-SIV or AES-SIV. To mount an attack, the applications must\nimplement their own protocol and use the EVP interface. Also they must skip the\nciphertext update when a message with an empty ciphertext arrives.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as these algorithms are not FIPS approved and the affected code is\noutside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"69e7069bcc12bfaa","cpes":["cpe:2.3:a:libcap2:libcap2:1\\:2.66-5ubuntu2.2:*:*:*:*:*:*:*"],"name":"libcap2","purl":"pkg:deb/ubuntu/libcap2@1%3A2.66-5ubuntu2.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1:2.66-5ubuntu2.2","language":"","licenses":["BSD-3-clause","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcap2/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libcap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcap2:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libcap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1:2.66-5ubuntu2.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4878","versionConstraint":"< 1:2.66-5ubuntu2.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libcap2","version":"1:2.66-5ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4878","fix":{"state":"fixed","versions":["1:2.66-5ubuntu2.4"],"available":[{"date":"2026-04-21","kind":"advisory","version":"1:2.66-5ubuntu2.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4878","date":"2026-10-08","epss":0.00141,"percentile":0.02978}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4878"},"relatedVulnerabilities":[{"id":"CVE-2026-4878","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4878","cwe":"CWE-367","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4878","date":"2026-10-08","epss":0.00141,"percentile":0.02978}],"urls":["https://access.redhat.com/errata/RHSA-2026:12423","https://access.redhat.com/errata/RHSA-2026:12441","https://access.redhat.com/errata/RHSA-2026:13285","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:19130","https://access.redhat.com/errata/RHSA-2026:19346","https://access.redhat.com/errata/RHSA-2026:19456","https://access.redhat.com/errata/RHSA-2026:19458","https://access.redhat.com/errata/RHSA-2026:20595","https://access.redhat.com/errata/RHSA-2026:21254","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:22634","https://access.redhat.com/errata/RHSA-2026:22957","https://access.redhat.com/errata/RHSA-2026:23233","https://access.redhat.com/errata/RHSA-2026:23245","https://access.redhat.com/errata/RHSA-2026:24346","https://access.redhat.com/errata/RHSA-2026:25044","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:25181","https://access.redhat.com/errata/RHSA-2026:26542","https://access.redhat.com/errata/RHSA-2026:27998","https://access.redhat.com/errata/RHSA-2026:28887","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:34098","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:7473","https://access.redhat.com/security/cve/CVE-2026-4878","https://bugzilla.redhat.com/show_bug.cgi?id=2447554","https://bugzilla.redhat.com/show_bug.cgi?id=2451615","http://www.openwall.com/lists/oss-security/2026/04/07/14","http://www.openwall.com/lists/oss-security/2026/04/07/4","http://www.openwall.com/lists/oss-security/2026/04/08/9","http://www.openwall.com/lists/oss-security/2026/04/09/5","http://www.openwall.com/lists/oss-security/2026/04/09/6","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4878","description":"A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation."}]},{"artifact":{"id":"059ac6c07034f18c","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3build1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3build1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.0696,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75803"},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75803","versionConstraint":"< 3.0.13-0ubuntu3.15 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.15"],"available":[{"date":"2026-08-25","kind":"advisory","version":"3.0.13-0ubuntu3.15"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.0696,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75803"},"relatedVulnerabilities":[{"id":"CVE-2026-75803","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."}]},{"artifact":{"id":"1c58aaf5ad1b37f3","cpes":["cpe:2.3:a:sed:sed:4.9-2build1:*:*:*:*:*:*:*"],"name":"sed","purl":"pkg:deb/ubuntu/sed@4.9-2build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"4.9-2build1","language":"","licenses":["BSD-4-clause-UC","BSL-1","GFDL-1.3","GFDL-NIV-1.3+","GPL-3","GPL-3+","ISC","X11","pcre"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/sed/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/sed/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sed.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/sed.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/sed.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/sed.list"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.9-2ubuntu0.24.04.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5958","versionConstraint":"< 4.9-2ubuntu0.24.04.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"sed","version":"4.9-2build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-5958","fix":{"state":"fixed","versions":["4.9-2ubuntu0.24.04.1"],"available":[{"date":"2026-05-04","kind":"advisory","version":"4.9-2ubuntu0.24.04.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-5958","cwe":"CWE-367","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-5958","date":"2026-10-08","epss":0.00137,"percentile":0.02701}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-5958"},"relatedVulnerabilities":[{"id":"CVE-2026-5958","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5958","cwe":"CWE-367","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-5958","date":"2026-10-08","epss":0.00137,"percentile":0.02701}],"urls":["https://cert.pl/en/posts/2026/04/CVE-2026-5958","https://www.gnu.org/software/sed/","http://www.openwall.com/lists/oss-security/2026/05/13/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5958","description":"When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: \n1. resolves symlink to its target and stores the resolved path for determining when output is written,\n2. opens the original symlink path (not the resolved one) to read the file. \nBetween these two calls there is a race window. If an attacker atomically replaces the symlink with a different target during that window, sed will: read content from the new (attacker-chosen) symlink target and write the processed result to the path recorded in step 1. This can lead to arbitrary file overwrite with attacker-controlled content in the context of the sed process.\n\n\nThis issue was fixed in version 4.10."}]},{"artifact":{"id":"22cdb1f439b32551","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/ubuntu/libssl3t64@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04&upstream=openssl","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.0666,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75805"},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"e7bc5a5123da05cb","cpes":["cpe:2.3:a:openssl:openssl:3.0.13-0ubuntu3.7:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/ubuntu/openssl@3.0.13-0ubuntu3.7?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.0.13-0ubuntu3.7","language":"","licenses":[],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13-0ubuntu3.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.0.13-0ubuntu3.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openssl","version":"3.0.13-0ubuntu3.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.0.13-0ubuntu3.16"],"available":[{"date":"2026-09-29","kind":"advisory","version":"3.0.13-0ubuntu3.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.0666,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75805"},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"c4aa126a69f7c083","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.2:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.2?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.2","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"fix":{"suggestedVersion":"5.38.2-3.2ubuntu0.4"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15649","versionConstraint":"< 5.38.2-3.2ubuntu0.4 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15649","fix":{"state":"fixed","versions":["5.38.2-3.2ubuntu0.4"],"available":[{"date":"2026-08-27","kind":"advisory","version":"5.38.2-3.2ubuntu0.4"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"risk":0.0635,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15649"},"relatedVulnerabilities":[{"id":"CVE-2025-15649","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15649","cwe":"CWE-248","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2025-15649","date":"2026-10-08","epss":0.00127,"percentile":0.02075}],"urls":["https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8.patch","https://github.com/pmqs/IO-Compress/issues/65","https://metacpan.org/release/PMQS/IO-Compress-2.215/changes","http://www.openwall.com/lists/oss-security/2026/05/27/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15649","description":"IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.\n\n_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.\n\nThe exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.059000000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27456"},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.059000000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27456"},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.059000000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27456"},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.059000000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27456"},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.059000000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27456"},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.059000000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27456"},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-27456","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27456","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"risk":0.059000000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27456"},"relatedVulnerabilities":[{"id":"CVE-2026-27456","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27456","cwe":"CWE-59","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-269","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27456","cwe":"CWE-367","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27456","date":"2026-10-08","epss":0.00118,"percentile":0.01571}],"urls":["https://github.com/util-linux/util-linux/commit/5e390467b26a3cf3fecc04e1a0d482dff3162fc4","https://github.com/util-linux/util-linux/releases/tag/v2.41.4","https://github.com/util-linux/util-linux/security/advisories/GHSA-qq4x-vfq4-9h9g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27456","description":"util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4."}]},{"artifact":{"id":"18ce0375cc5bec3f","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/ubuntu/libncursesw6@6.4%2B20240113-1ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"< 6.4+20240113-1ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.2"],"available":[{"date":"2026-09-01","kind":"advisory","version":"6.4+20240113-1ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.0588,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6141"},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"9d92803c72cb7a13","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/ubuntu/libtinfo6@6.4%2B20240113-1ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"< 6.4+20240113-1ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.2"],"available":[{"date":"2026-09-01","kind":"advisory","version":"6.4+20240113-1ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.0588,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6141"},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"9ce712b33a96bea6","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/ubuntu/ncurses-base@6.4%2B20240113-1ubuntu2?arch=all&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"< 6.4+20240113-1ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.2"],"available":[{"date":"2026-09-01","kind":"advisory","version":"6.4+20240113-1ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.0588,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6141"},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"e94839bb1b1744f0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.4\\+20240113-1ubuntu2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/ubuntu/ncurses-bin@6.4%2B20240113-1ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=ncurses","type":"deb","version":"6.4+20240113-1ubuntu2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"fix":{"suggestedVersion":"6.4+20240113-1ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"< 6.4+20240113-1ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ncurses","version":"6.4+20240113-1ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"fixed","versions":["6.4+20240113-1ubuntu2.2"],"available":[{"date":"2026-09-01","kind":"advisory","version":"6.4+20240113-1ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"risk":0.0588,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-6141"},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-08","epss":0.00196,"percentile":0.08547}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"ac4c65178408e21f","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"fix":{"suggestedVersion":"1:1.3.dfsg-3.1ubuntu2.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"< 1:1.3.dfsg-3.1ubuntu2.2 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"fixed","versions":["1:1.3.dfsg-3.1ubuntu2.2"],"available":[{"date":"2026-08-31","kind":"advisory","version":"1:1.3.dfsg-3.1ubuntu2.2"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"risk":0.0573,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-27171"},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-08","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"c666aef9f22ed237","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-5.1build0.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-5.1build0.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-5.1build0.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-5.1build0.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-5.1build0.1:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-5.1build0.1:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/ubuntu/libbz2-1.0@1.0.8-5.1build0.1?arch=amd64&distro=ubuntu-24.04&upstream=bzip2","type":"deb","version":"1.0.8-5.1build0.1","language":"","licenses":["BSD-variant","GPL-2"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2"}]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.8-5.1ubuntu0.1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"< 1.0.8-5.1ubuntu0.1 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"bzip2","version":"1.0.8-5.1build0.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"fixed","versions":["1.0.8-5.1ubuntu0.1"],"available":[{"date":"2026-08-27","kind":"advisory","version":"1.0.8-5.1ubuntu0.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"risk":0.054599999999999996,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-42250"},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-08","epss":0.00182,"percentile":0.07166}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"6860f54cb4c4abbc","cpes":["cpe:2.3:a:docker:docker:v25.0.6\\+incompatible:*:*:*:*:*:*:*"],"name":"github.com/docker/docker","purl":"pkg:golang/github.com/docker/docker@v25.0.6%2Bincompatible","type":"go-module","version":"v25.0.6+incompatible","language":"go","licenses":[],"metadata":{"h1Digest":"h1:5cPwbwriIcsua2REJe8HqQV+6WlWc1byg2QSXzBxBGg=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vp62-88p7-qqf5","versionConstraint":"<=28.5.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/docker/docker","version":"v25.0.6+incompatible"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-vp62-88p7-qqf5","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41568","cwe":"CWE-81","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41568","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41568","date":"2026-10-08","epss":0.00098,"percentile":0.0072}],"risk":0.054389999999999994,"urls":["https://github.com/moby/moby/security/advisories/GHSA-vp62-88p7-qqf5","https://nvd.nist.gov/vuln/detail/CVE-2026-41568"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vp62-88p7-qqf5","description":"Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap"},"relatedVulnerabilities":[{"id":"CVE-2026-41568","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":0.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41568","cwe":"CWE-81","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41568","cwe":"CWE-367","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41568","date":"2026-10-08","epss":0.00098,"percentile":0.0072}],"urls":["https://github.com/moby/moby/security/advisories/GHSA-vp62-88p7-qqf5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41568","description":"Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14."}]},{"artifact":{"id":"34d771df3f22594b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.0535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6368"},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"cda8bf47e0256df5","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.7:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.7?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.7","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39-0ubuntu8.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6368","versionConstraint":"< 2.39-0ubuntu8.9 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6368","fix":{"state":"fixed","versions":["2.39-0ubuntu8.9"],"available":[{"date":"2026-09-10","kind":"advisory","version":"2.39-0ubuntu8.9"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"risk":0.0535,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6368"},"relatedVulnerabilities":[{"id":"CVE-2026-6368","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6368","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6368","date":"2026-10-08","epss":0.00107,"percentile":0.01073}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34090","https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6368","description":"Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"a3f8efd41b6d8f41","cpes":["cpe:2.3:a:snowflakedb:gosnowflake:v1.13.3:*:*:*:*:*:*:*"],"name":"github.com/snowflakedb/gosnowflake","purl":"pkg:golang/github.com/snowflakedb/gosnowflake@v1.13.3","type":"go-module","version":"v1.13.3","language":"go","licenses":[],"metadata":{"h1Digest":"h1:udARwDZ+Eb7TnihuMno1CaNVUDbJnikWC+8p4RCJQBk=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qqj6-54q6-cxv6","versionConstraint":"<=1.19.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/snowflakedb/gosnowflake","version":"v1.13.3"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qqj6-54q6-cxv6","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86597","cwe":"CWE-532","type":"Secondary","source":"412d305a-227d-44f9-a262-a31ba44f2aea"}],"epss":[{"cve":"CVE-2026-86597","date":"2026-10-08","epss":0.00089,"percentile":0.00397}],"risk":0.05117499999999999,"urls":["https://github.com/snowflakedb/snowflake-connector-nodejs/security/advisories/GHSA-qqj6-54q6-cxv6","https://nvd.nist.gov/vuln/detail/CVE-2026-86597","https://docs.snowflake.com/en/release-notes/clients-drivers/golang-2026#version-220-sep-03-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/jdbc-2026#version-434-sep-03-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/nodejs-2026#version-330-september-3-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/odbc-2026#version-3200-sep-3-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/php-pdo-2026#version-420-sep-3-2026","https://github.com/snowflakedb/snowflake-connector-python/releases/tag/v4.7.3"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qqj6-54q6-cxv6","description":"Snowflake drivers writes sensitive information to logs"},"relatedVulnerabilities":[{"id":"CVE-2026-86597","cvss":[{"type":"Secondary","source":"412d305a-227d-44f9-a262-a31ba44f2aea","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86597","cwe":"CWE-532","type":"Secondary","source":"412d305a-227d-44f9-a262-a31ba44f2aea"}],"epss":[{"cve":"CVE-2026-86597","date":"2026-10-08","epss":0.00089,"percentile":0.00397}],"urls":["https://docs.snowflake.com/en/release-notes/clients-drivers/golang-2026#version-220-sep-03-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/jdbc-2026#version-434-sep-03-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/nodejs-2026#version-330-september-3-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/odbc-2026#version-3200-sep-3-2026","https://docs.snowflake.com/en/release-notes/clients-drivers/php-pdo-2026#version-420-sep-3-2026","https://github.com/snowflakedb/snowflake-connector-python/releases/tag/v4.7.3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86597","description":"Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did not cover all affected log paths and data types. An attacker with read access to the log destination, whether the local filesystem, a log aggregation service, or a CI/CD artifact store, could obtain credentials and decryption keys that, if still valid at the time of access, could be used to authenticate to the corresponding Snowflake account or cloud-storage object. Successful exploitation requires read access to the log destination, and impact is bounded by credential lifetime and object scope. The fix is available in Snowflake Connector for Python v4.7.3, Snowflake Go Driver v2.2.0, Snowflake JDBC Driver v4.3.4 (including the snowflake-jdbc-fips and snowflake-jdbc-thin), Snowflake Node.js Driver v3.3.0, Snowflake PHP PDO Driver v4.2.0, and Snowflake ODBC Driver v3.20.0. Users must manually upgrade and should securely delete previously generated diagnostic logs containing sensitive information where retention is not required."}]},{"artifact":{"id":"222d25a1a40f34f4","cpes":["cpe:2.3:a:cilium:ebpf:v0.12.3:*:*:*:*:*:*:*"],"name":"github.com/cilium/ebpf","purl":"pkg:golang/github.com/cilium/ebpf@v0.12.3","type":"go-module","version":"v0.12.3","language":"go","licenses":[],"metadata":{"h1Digest":"h1:8ht6F9MquybnY97at+VDZb3eQQr8ev79RueWeVaEcG4=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.22.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xhgw-qwwf-pg32","versionConstraint":"<0.22.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/cilium/ebpf","version":"v0.12.3"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-xhgw-qwwf-pg32","fix":{"state":"fixed","versions":["0.22.0"],"available":[{"date":"2026-08-17","kind":"first-observed","version":"0.22.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10722","cwe":"CWE-189","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-10722","cwe":"CWE-190","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-10722","date":"2026-10-08","epss":0.00179,"percentile":0.06813}],"risk":0.05011999999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-10722","https://github.com/cilium/ebpf/issues/2019","https://github.com/cilium/ebpf/pull/2021","https://github.com/cilium/ebpf/commit/533dfc82fd228bfadf42ea7180c39de7d9af47fa","https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815","https://github.com/cilium/ebpf","https://vuldb.com/cve/CVE-2026-10722","https://vuldb.com/submit/818291","https://vuldb.com/vuln/368091","https://vuldb.com/vuln/368091/cti"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xhgw-qwwf-pg32","description":"ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader"},"relatedVulnerabilities":[{"id":"CVE-2026-10722","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10722","cwe":"CWE-189","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-10722","cwe":"CWE-190","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-10722","date":"2026-10-08","epss":0.00179,"percentile":0.06813}],"urls":["https://gist.github.com/thesmartshadow/256bff0f8042c584f993ace89074a815","https://github.com/cilium/ebpf/","https://github.com/cilium/ebpf/commit/533dfc82fd228bfadf42ea7180c39de7d9af47fa","https://github.com/cilium/ebpf/issues/2019","https://github.com/cilium/ebpf/pull/2021","https://vuldb.com/cve/CVE-2026-10722","https://vuldb.com/submit/818291","https://vuldb.com/vuln/368091","https://vuldb.com/vuln/368091/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10722","description":"A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue."}]},{"artifact":{"id":"b31c0db779c05936","cpes":["cpe:2.3:a:golang:x\\/sys:v0.38.0:*:*:*:*:*:*:*"],"name":"golang.org/x/sys","purl":"pkg:golang/golang.org/x/sys@v0.38.0","type":"go-module","version":"v0.38.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:3yZWxaJjBmCWXqhN1qh02AkOnCQ1poK6oF+a7xWL6Gc=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.44.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5024","versionConstraint":"<0.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/sys","version":"v0.38.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5024","fix":{"state":"fixed","versions":["0.44.0"],"available":[{"date":"2026-04-23","kind":"release","version":"0.44.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"risk":0.04976999999999999,"urls":["https://go.dev/cl/770080","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78916","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."},"relatedVulnerabilities":[{"id":"CVE-2026-39824","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"urls":["https://go.dev/cl/770080","https://go.dev/issue/78916","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg","https://pkg.go.dev/vuln/GO-2026-5024"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39824","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."}]},{"artifact":{"id":"6860f54cb4c4abbc","cpes":["cpe:2.3:a:docker:docker:v25.0.6\\+incompatible:*:*:*:*:*:*:*"],"name":"github.com/docker/docker","purl":"pkg:golang/github.com/docker/docker@v25.0.6%2Bincompatible","type":"go-module","version":"v25.0.6+incompatible","language":"go","licenses":[],"metadata":{"h1Digest":"h1:5cPwbwriIcsua2REJe8HqQV+6WlWc1byg2QSXzBxBGg=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"25.0.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-4vq8-7jfc-9cvp","versionConstraint":"<=25.0.12 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/docker/docker","version":"v25.0.6+incompatible"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-4vq8-7jfc-9cvp","fix":{"state":"fixed","versions":["25.0.13"],"available":[{"date":"2026-03-28","kind":"first-observed","version":"25.0.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":2.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-54410","cwe":"CWE-909","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-54410","date":"2026-10-08","epss":0.00155,"percentile":0.04082}],"risk":0.04882499999999999,"urls":["https://github.com/moby/moby/security/advisories/GHSA-4vq8-7jfc-9cvp","https://nvd.nist.gov/vuln/detail/CVE-2025-54410","https://firewalld.org/documentation/howto/reload-firewalld.html","https://github.com/moby/moby/pull/49443","https://github.com/moby/moby/pull/49728"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-4vq8-7jfc-9cvp","description":"Moby firewalld reload removes bridge network isolation"},"relatedVulnerabilities":[{"id":"CVE-2025-54410","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.2,"impactScore":2.8,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":2.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-54410","cwe":"CWE-909","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-54410","date":"2026-10-08","epss":0.00155,"percentile":0.04082}],"urls":["https://firewalld.org/documentation/howto/reload-firewalld.html","https://github.com/moby/moby/security/advisories/GHSA-4vq8-7jfc-9cvp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-54410","description":"Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that isolate bridge networks, allowing any container to access all ports on any other container across different bridge networks on the same host. This breaks network segmentation between containers that should be isolated, creating significant risk in multi-tenant environments. Only containers in --internal networks remain protected.\nWorkarounds include reloading firewalld and either restarting the docker daemon, re-creating bridge networks, or using rootless mode. Maintainers anticipate a fix for this issue in version 25.0.13."}]},{"artifact":{"id":"648b64958af18a7b","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:t6wl9SPayj+c7lEIFgm4ooDBZVb01IhLB4InpomhRw8=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"84fe6a9d4f786cbf","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace\\/otlptracegrpc:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mw5xcxMwlqoJd97vwPxA8isEaIoxsta9/Q51+TTJLGE=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"02ffa4a48a219768","cpes":["cpe:2.3:a:otel:exporters\\/otlp\\/otlptrace\\/otlptracehttp:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp","purl":"pkg:golang/go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Xw8U6u2f8DK2XAkGRFV7BBLENgnTGX9i4rQRxJf+/vs=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"a6bbe16f49176f0a","cpes":["cpe:2.3:a:otel:sdk:v1.24.0:*:*:*:*:*:*:*"],"name":"go.opentelemetry.io/otel/sdk","purl":"pkg:golang/go.opentelemetry.io/otel/sdk@v1.24.0","type":"go-module","version":"v1.24.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:YMPPDNymmQN3ZgczicBY3B6sf9n62Dlj9pWD3ucgoDw=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8wmf-6v46-5gfg","versionConstraint":">=1.5.0,<=1.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"go.opentelemetry.io/otel/sdk","version":"v1.24.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-8wmf-6v46-5gfg","fix":{"state":"fixed","versions":["1.45.0"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"1.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"risk":0.048749999999999995,"urls":["https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg","https://nvd.nist.gov/vuln/detail/CVE-2026-81870","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8wmf-6v46-5gfg","description":"OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs"},"relatedVulnerabilities":[{"id":"CVE-2026-81870","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-81870","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-81870","cwe":"CWE-532","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-81870","date":"2026-10-08","epss":0.00195,"percentile":0.08426}],"urls":["https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38","https://github.com/open-telemetry/opentelemetry-go/pull/8438","https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/zipkin/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/v1.45.0","https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-81870","description":"OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively include span processor, exporter, and client configuration. Applications that call otel.SetLogger to enable OpenTelemetry internal Info logging can therefore record OTLP gRPC and HTTP collector endpoints, the OTLP HTTP Insecure flag, and complete Zipkin collector URLs. A person or system with access to those logs can learn internal collector topology and can recover credentials or tokens embedded in Zipkin URL user information or query strings. The default OpenTelemetry logger does not emit the event, and this path does not log OTLP authentication headers, TLS key material, or span payloads. This issue is fixed in version 1.45.0."}]},{"artifact":{"id":"1855f796e9291224","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"255.4-1ubuntu8.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40226","versionConstraint":"< 255.4-1ubuntu8.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40226","fix":{"state":"fixed","versions":["255.4-1ubuntu8.16"],"available":[{"date":"2026-06-08","kind":"advisory","version":"255.4-1ubuntu8.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-08","epss":0.00094,"percentile":0.00573}],"risk":0.047,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40226"},"relatedVulnerabilities":[{"id":"CVE-2026-40226","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-08","epss":0.00094,"percentile":0.00573}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-9mj4-rrc3-gjcx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40226","description":"In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file."}]},{"artifact":{"id":"e3b5cb8c2c8c33bf","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"255.4-1ubuntu8.16"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40226","versionConstraint":"< 255.4-1ubuntu8.16 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40226","fix":{"state":"fixed","versions":["255.4-1ubuntu8.16"],"available":[{"date":"2026-06-08","kind":"advisory","version":"255.4-1ubuntu8.16"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-08","epss":0.00094,"percentile":0.00573}],"risk":0.047,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40226"},"relatedVulnerabilities":[{"id":"CVE-2026-40226","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40226","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40226","date":"2026-10-08","epss":0.00094,"percentile":0.00573}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-9mj4-rrc3-gjcx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40226","description":"In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file."}]},{"artifact":{"id":"c523498c8ece7464","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.4:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.4?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.4","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.4.4-2ubuntu17.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57062","versionConstraint":"< 2.4.4-2ubuntu17.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57062","fix":{"state":"fixed","versions":["2.4.4-2ubuntu17.6"],"available":[{"date":"2026-09-03","kind":"advisory","version":"2.4.4-2ubuntu17.6"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-57062","date":"2026-10-08","epss":0.00149,"percentile":0.03583}],"risk":0.0447,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57062"},"relatedVulnerabilities":[{"id":"CVE-2026-57062","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57062","cwe":"CWE-1284","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-57062","date":"2026-10-08","epss":0.00149,"percentile":0.03583}],"urls":["https://blog.calif.io/p/how-to-format-a-ciphertext","https://www.gnupg.org/download/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57062","description":"CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182."}]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.17.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm2x-2g9h-ccm8","versionConstraint":"<=5.17.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-gm2x-2g9h-ccm8","fix":{"state":"fixed","versions":["5.17.1"],"available":[{"date":"2026-03-31","kind":"first-observed","version":"5.17.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33762","cwe":"CWE-129","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33762","date":"2026-10-08","epss":0.00153,"percentile":0.03905}],"risk":0.04436999999999999,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-gm2x-2g9h-ccm8","https://nvd.nist.gov/vuln/detail/CVE-2026-33762","https://github.com/go-git/go-git/releases/tag/v5.17.1"],"severity":"Low","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm2x-2g9h-ccm8","description":"go-git missing validation decoding Index v4 files leads to panic"},"relatedVulnerabilities":[{"id":"CVE-2026-33762","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.8,"impactScore":1.5,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33762","cwe":"CWE-129","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33762","date":"2026-10-08","epss":0.00153,"percentile":0.03905}],"urls":["https://github.com/go-git/go-git/releases/tag/v5.17.1","https://github.com/go-git/go-git/security/advisories/GHSA-gm2x-2g9h-ccm8"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33762","description":"go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing. This issue only affects Git index format version 4. Earlier formats (go-git supports only v2 and v3) are not vulnerable to this issue. This issue has been patched in version 5.17.1."}]},{"artifact":{"id":"1855f796e9291224","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"e3b5cb8c2c8c33bf","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"059ac6c07034f18c","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3build1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3build1?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3build1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"c523498c8ece7464","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.4:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.4?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.4","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4602","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4602","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"risk":0.03245,"urls":["https://go.dev/issue/77827","https://go.dev/cl/749480"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened.\n\nThe impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."},"relatedVulnerabilities":[{"id":"CVE-2026-27139","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"urls":["https://go.dev/cl/749480","https://go.dev/issue/77827","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4602"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27139","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."}]},{"artifact":{"id":"1855f796e9291224","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"255.4-1ubuntu8.17"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"< 255.4-1ubuntu8.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"fixed","versions":["255.4-1ubuntu8.17"],"available":[{"date":"2026-08-10","kind":"advisory","version":"255.4-1ubuntu8.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"risk":0.028499999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-16742"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"e3b5cb8c2c8c33bf","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.14:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.14?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.14","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"fix":{"suggestedVersion":"255.4-1ubuntu8.17"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-16742","versionConstraint":"< 255.4-1ubuntu8.17 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-16742","fix":{"state":"fixed","versions":["255.4-1ubuntu8.17"],"available":[{"date":"2026-08-10","kind":"advisory","version":"255.4-1ubuntu8.17"}]},"cvss":[],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"risk":0.028499999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-16742"},"relatedVulnerabilities":[{"id":"CVE-2026-16742","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.7,"impactScore":5.9,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16742","cwe":"CWE-269","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-16742","cwe":"CWE-347","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-16742","date":"2026-10-08","epss":0.00057,"percentile":0.00004}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-jm29-p7hh-vjhv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16742","description":"systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user"}]},{"artifact":{"id":"fc79954134fe2e5a","cpes":["cpe:2.3:a:google:grpc:v1.67.1:*:*:*:*:*:*:*"],"name":"google.golang.org/grpc","purl":"pkg:golang/google.golang.org/grpc@v1.67.1","type":"go-module","version":"v1.67.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:zWnc1Vrcno+lHZCOofnIMvycFcc0QRGIzm9dhnDX68E=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.82.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hrxh-6v49-42gf","versionConstraint":"<1.82.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"google.golang.org/grpc","version":"v1.67.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-hrxh-6v49-42gf","fix":{"state":"fixed","versions":["1.82.1"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"1.82.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/grpc/grpc-go/security/advisories/GHSA-hrxh-6v49-42gf","https://github.com/grpc/grpc-go/pull/9236","https://github.com/grpc/grpc-go/commit/4ea465d4ab98013f72a142fe0fc89c19770b2935","https://github.com/grpc/grpc-go/releases/tag/v1.82.1"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hrxh-6v49-42gf","description":"gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities"},"relatedVulnerabilities":[]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53612","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53612"},"relatedVulnerabilities":[{"id":"CVE-2026-53612","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53614","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53614"},"relatedVulnerabilities":[{"id":"CVE-2026-53614","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"3c0ad287e54229a6","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.5","type":"deb","version":"1:2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.5"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"385fa5bfb7139f18","cpes":["cpe:2.3:a:aws:aws-sdk-go-v2\\/aws\\/protocol\\/eventstream:v1.6.2:*:*:*:*:*:*:*","cpe:2.3:a:aws:aws_sdk_go_v2\\/aws\\/protocol\\/eventstream:v1.6.2:*:*:*:*:*:*:*"],"name":"github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream","purl":"pkg:golang/github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.6.2","type":"go-module","version":"v1.6.2","language":"go","licenses":[],"metadata":{"h1Digest":"h1:x6xsQXGSmW6frevwDA+vi/wqhp1ct18mVXYN08/93to=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.7.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xmrv-pmrh-hhx2","versionConstraint":"<1.7.8 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream","version":"v1.6.2"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-xmrv-pmrh-hhx2","fix":{"state":"fixed","versions":["1.7.8"],"available":[{"date":"2026-04-08","kind":"first-observed","version":"1.7.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/aws/aws-sdk-go-v2/security/advisories/GHSA-xmrv-pmrh-hhx2","https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xmrv-pmrh-hhx2","description":"Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder"},"relatedVulnerabilities":[]},{"artifact":{"id":"f3f743de9daa7ae9","cpes":["cpe:2.3:a:aws:aws-sdk-go-v2\\/service\\/s3:v1.53.1:*:*:*:*:*:*:*","cpe:2.3:a:aws:aws_sdk_go_v2\\/service\\/s3:v1.53.1:*:*:*:*:*:*:*"],"name":"github.com/aws/aws-sdk-go-v2/service/s3","purl":"pkg:golang/github.com/aws/aws-sdk-go-v2/service/s3@v1.53.1","type":"go-module","version":"v1.53.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:6cnno47Me9bRykw9AEv9zkXE+5or7jz8TsskTTccbgc=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.97.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xmrv-pmrh-hhx2","versionConstraint":"<1.97.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/aws/aws-sdk-go-v2/service/s3","version":"v1.53.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-xmrv-pmrh-hhx2","fix":{"state":"fixed","versions":["1.97.3"],"available":[{"date":"2026-04-08","kind":"first-observed","version":"1.97.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/aws/aws-sdk-go-v2/security/advisories/GHSA-xmrv-pmrh-hhx2","https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xmrv-pmrh-hhx2","description":"Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder"},"relatedVulnerabilities":[]},{"artifact":{"id":"fce19d1dbb981d3d","cpes":["cpe:2.3:a:go-git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go-git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go_git:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go-git\\/v5:v5.13.1:*:*:*:*:*:*:*","cpe:2.3:a:go:go_git\\/v5:v5.13.1:*:*:*:*:*:*:*"],"name":"github.com/go-git/go-git/v5","purl":"pkg:golang/github.com/go-git/go-git/v5@v5.13.1","type":"go-module","version":"v5.13.1","language":"go","licenses":[],"metadata":{"h1Digest":"h1:DAQ9APonnlvSWpvolXWIuV6Q6zXy2wHbN4cVlNR5Q+M=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"5.19.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w5pp-99ch-qj29","versionConstraint":"<=5.19.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/go-git/go-git/v5","version":"v5.13.1"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w5pp-99ch-qj29","fix":{"state":"fixed","versions":["5.19.1"],"available":[{"date":"2026-05-30","kind":"first-observed","version":"5.19.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/go-git/go-git/security/advisories/GHSA-w5pp-99ch-qj29"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w5pp-99ch-qj29","description":"go-git: Malformed Git object data may cause panics or resource exhaustion"},"relatedVulnerabilities":[]},{"artifact":{"id":"44c177ef32b95dd0","cpes":["cpe:2.3:a:gorilla:websocket:v1.5.0:*:*:*:*:*:*:*"],"name":"github.com/gorilla/websocket","purl":"pkg:golang/github.com/gorilla/websocket@v1.5.0","type":"go-module","version":"v1.5.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:PPwGk2jz7EePpoHN/+ClbZu8SPxiqlu12wZP/3sWmnc=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w67g-5rqw-f597","versionConstraint":"<1.5.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/gorilla/websocket","version":"v1.5.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w67g-5rqw-f597","fix":{"state":"fixed","versions":["1.5.3"],"available":[{"date":"2026-08-25","kind":"first-observed","version":"1.5.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/canolgun-commits/websocket/security/advisories/GHSA-w67g-5rqw-f597","https://github.com/gorilla/websocket/commit/d67f41855da42d7bccd9ef050c49f7e54e783b95","https://github.com/gorilla/websocket/releases/tag/v1.5.3"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w67g-5rqw-f597","description":"Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key"},"relatedVulnerabilities":[]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53612","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53612"},"relatedVulnerabilities":[{"id":"CVE-2026-53612","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53614","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53614"},"relatedVulnerabilities":[{"id":"CVE-2026-53614","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"39ee0553a5289e3b","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53612","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53612"},"relatedVulnerabilities":[{"id":"CVE-2026-53612","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53614","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53614"},"relatedVulnerabilities":[{"id":"CVE-2026-53614","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"9c3ce62925a3c63c","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53612","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53612"},"relatedVulnerabilities":[{"id":"CVE-2026-53612","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53614","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53614"},"relatedVulnerabilities":[{"id":"CVE-2026-53614","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"e9ce5bacf834f391","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53612","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53612"},"relatedVulnerabilities":[{"id":"CVE-2026-53612","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53614","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53614"},"relatedVulnerabilities":[{"id":"CVE-2026-53614","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"12e93d3f2a68625a","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53612","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53612"},"relatedVulnerabilities":[{"id":"CVE-2026-53612","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53614","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53614"},"relatedVulnerabilities":[{"id":"CVE-2026-53614","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"acbdafc6d61c681f","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53612","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53612","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53612"},"relatedVulnerabilities":[{"id":"CVE-2026-53612","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53613","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53613","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53613"},"relatedVulnerabilities":[{"id":"CVE-2026-53613","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53614","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53614","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53614"},"relatedVulnerabilities":[{"id":"CVE-2026-53614","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"5b3469dc9628ba1a","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.5:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.5","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:f2a7f072635332d307212e318e07284948b89f4167fce5c4d7c9cfb7590b74b6","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:343d6feb82d71120cb4a25106beb8690f0244f634dbfd9304223457881034bd2","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.39.3-9ubuntu6.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-53615","versionConstraint":"< 2.39.3-9ubuntu6.6 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-53615","fix":{"state":"fixed","versions":["2.39.3-9ubuntu6.6"],"available":[{"date":"2026-08-31","kind":"advisory","version":"2.39.3-9ubuntu6.6"}]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-53615"},"relatedVulnerabilities":[{"id":"CVE-2026-53615","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"c93205ae73c675ea","cpes":["cpe:2.3:a:klauspost:compress:v1.17.11:*:*:*:*:*:*:*"],"name":"github.com/klauspost/compress","purl":"pkg:golang/github.com/klauspost/compress@v1.17.11","type":"go-module","version":"v1.17.11","language":"go","licenses":[],"metadata":{"h1Digest":"h1:In6xLpyWOi1+C7tXUUWv2ot1QvBjxevKAaI6IXrJmUc=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5841","versionConstraint":">=1.16.0,<1.18.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/klauspost/compress","version":"v1.17.11"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5841","fix":{"state":"fixed","versions":["1.18.7"],"available":[{"date":"2026-06-30","kind":"release","version":"1.18.7"}]},"cvss":[],"risk":0,"urls":["https://github.com/klauspost/compress/commit/8668e357e776d5152ed62f33c17f21b8690664fa"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw","description":"Providing a specially crafted dictionary to s2.NewDict and using it to encode data can make the encoder read out of bounds."},"relatedVulnerabilities":[{"id":"GHSA-259r-337f-4rfw","cvss":[],"urls":[],"severity":"Unknown","namespace":"github:language:go","dataSource":"github"}]},{"artifact":{"id":"b885856fe85877ab","cpes":["cpe:2.3:a:golang:crypto:v0.45.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.45.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.45.0","type":"go-module","version":"v0.45.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:jMBrvKuj23MTlT0bQEOBcAE0mjg8mK9RXFhRH6nyF3Q=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5932","versionConstraint":"none (unknown)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.45.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5932","fix":{"state":"","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/44226","description":"The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.\n\nIf you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package."},"relatedVulnerabilities":[]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"bd6362045779c694","cpes":["cpe:2.3:a:golang:networking:v0.47.0:*:*:*:*:go:*:*","cpe:2.3:a:golang:net:v0.47.0:*:*:*:*:go:*:*"],"name":"golang.org/x/net","purl":"pkg:golang/golang.org/x/net@v0.47.0","type":"go-module","version":"v0.47.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=","mainModule":"github.com/grafana/agent","architecture":"amd64","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.60.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<0.60.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/net","version":"v0.47.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["0.60.0"],"available":[{"date":"2026-10-08","kind":"release","version":"0.60.0"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"5e681839454d4e08","cpes":["cpe:2.3:a:golang:go:1.25.7:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.25.7","type":"go-module","version":"go1.25.7","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.25.7"},"locations":[{"path":"/usr/bin/grafana-agent","layerID":"sha256:f92a5cd006b5424494992a7255ab8d5c0f94f4dc79753a5879cfdc30f0a1e2e6","accessPath":"/usr/bin/grafana-agent","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.25.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:27:46.635Z","grype_db_version":"2026-10-09T06:32:32.000Z"}