{"grype_matches":[{"artifact":{"id":"97c784845da42004","cpes":["cpe:2.3:a:squizlabs\\/php-codesniffer:squizlabs\\/php-codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php-codesniffer:squizlabs\\/php_codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php_codesniffer:squizlabs\\/php-codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php_codesniffer:squizlabs\\/php_codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php:squizlabs\\/php-codesniffer:3.13.5:*:*:*:*:*:*:*","cpe:2.3:a:squizlabs\\/php:squizlabs\\/php_codesniffer:3.13.5:*:*:*:*:*:*:*"],"name":"squizlabs/php_codesniffer","purl":"pkg:composer/squizlabs/php_codesniffer@3.13.5","type":"php-composer","version":"3.13.5","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.13.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hmqg-cxww-wqhq","versionConstraint":"<3.13.6 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"squizlabs/php_codesniffer","version":"3.13.5"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-hmqg-cxww-wqhq","fix":{"state":"fixed","versions":["3.13.6"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"3.13.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67434","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-67434","date":"2026-10-08","epss":0.01063,"percentile":0.63605}],"risk":0.78662,"urls":["https://github.com/PHPCSStandards/PHP_CodeSniffer/security/advisories/GHSA-hmqg-cxww-wqhq","https://github.com/PHPCSStandards/PHP_CodeSniffer/pull/1473","https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/7a3a6bbf153a03fa3a9413afc60bded6b764e76b","https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/f0e1ebb0563f0e5d7f190497a787bcaf8474f3fe","https://github.com/FriendsOfPHP/security-advisories/blob/master/squizlabs/php_codesniffer/CVE-2026-67434.yaml","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/3.13.6","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/4.0.2"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hmqg-cxww-wqhq","description":"PHP_CodeSniffer gitblame report command injection via crafted filename"},"relatedVulnerabilities":[{"id":"CVE-2026-67434","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67434","cwe":"CWE-78","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-67434","date":"2026-10-08","epss":0.01063,"percentile":0.63605}],"urls":["https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/7a3a6bbf153a03fa3a9413afc60bded6b764e76b","https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/f0e1ebb0563f0e5d7f190497a787bcaf8474f3fe","https://github.com/PHPCSStandards/PHP_CodeSniffer/pull/1473","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/3.13.6","https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/4.0.2","https://github.com/PHPCSStandards/PHP_CodeSniffer/security/advisories/GHSA-hmqg-cxww-wqhq"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67434","description":"PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as \" and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63292","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63292","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"risk":0.657,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63292"},"relatedVulnerabilities":[{"id":"CVE-2026-63292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-08","epss":0.00876,"percentile":0.57735}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57941","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-57941","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"risk":0.5640000000000001,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-57941"},"relatedVulnerabilities":[{"id":"CVE-2026-57941","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-08","epss":0.006,"percentile":0.47084}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56154","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-56154","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"risk":0.5282800000000001,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-56154"},"relatedVulnerabilities":[{"id":"CVE-2026-56154","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-08","epss":0.00562,"percentile":0.45018}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59797","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59797","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"risk":0.4888,"urls":[],"severity":"Critical","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59797"},"relatedVulnerabilities":[{"id":"CVE-2026-59797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-08","epss":0.0052,"percentile":0.4236}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/22"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2q4p-g7hv-5rgv","versionConstraint":">=0.6.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-2q4p-g7hv-5rgv","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71488","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71488","cwe":"CWE-1050","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71488","date":"2026-10-08","epss":0.0063,"percentile":0.48561}],"risk":0.47250000000000003,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv","https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8","https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb","https://github.com/thephpleague/commonmark/commit/c97b02e5e652b992033b93ba5d6182f706343fc6","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2q4p-g7hv-5rgv","description":"league/commonmark: Quadratic-time denial of service when parsing crafted Markdown"},"relatedVulnerabilities":[{"id":"CVE-2026-71488","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71488","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71488","cwe":"CWE-1050","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71488","date":"2026-10-08","epss":0.0063,"percentile":0.48561}],"urls":["https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8","https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb","https://github.com/thephpleague/commonmark/commit/c97b02e5e652b992033b93ba5d6182f706343fc6","https://github.com/thephpleague/commonmark/releases/tag/2.9.0","https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71488","description":"league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56449","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-56449","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"risk":0.45899999999999996,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-56449"},"relatedVulnerabilities":[{"id":"CVE-2026-56449","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-08","epss":0.00612,"percentile":0.47682}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/18"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48005","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-48005","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"risk":0.4545,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-48005"},"relatedVulnerabilities":[{"id":"CVE-2026-48005","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-08","epss":0.00606,"percentile":0.47355}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/15"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63718","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63718","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63718"},"relatedVulnerabilities":[{"id":"CVE-2026-63718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-08","epss":0.00499,"percentile":0.4079}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56153","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-56153","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"risk":0.3735,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-56153"},"relatedVulnerabilities":[{"id":"CVE-2026-56153","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-08","epss":0.00498,"percentile":0.40748}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59685","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-59685","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59685","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59685","date":"2026-10-08","epss":0.00498,"percentile":0.40747}],"risk":0.3735,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-59685"},"relatedVulnerabilities":[{"id":"CVE-2026-59685","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59685","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59685","date":"2026-10-08","epss":0.00498,"percentile":0.40747}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/21"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59685","description":"Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63686","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63686","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63686"},"relatedVulnerabilities":[{"id":"CVE-2026-63686","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-08","epss":0.00478,"percentile":0.39275}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/25"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73637","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73637","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"risk":0.35816,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73637"},"relatedVulnerabilities":[{"id":"CVE-2026-73637","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-08","epss":0.00484,"percentile":0.39732}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/28"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93546","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-93546","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-93546"},"relatedVulnerabilities":[{"id":"CVE-2026-93546","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-08","epss":0.00436,"percentile":0.35914}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/30"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63045","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-63045","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"risk":0.35400000000000004,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-63045"},"relatedVulnerabilities":[{"id":"CVE-2026-63045","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-08","epss":0.00472,"percentile":0.38867}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46729","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-46729","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"risk":0.35100000000000003,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-46729"},"relatedVulnerabilities":[{"id":"CVE-2026-46729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-08","epss":0.00468,"percentile":0.38541}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54873","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.34650000000000003,"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73636","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-73636","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"risk":0.32136000000000003,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-73636"},"relatedVulnerabilities":[{"id":"CVE-2026-73636","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-08","epss":0.00412,"percentile":0.33442}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-79768","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-79768","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"risk":0.30385,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-79768"},"relatedVulnerabilities":[{"id":"CVE-2026-79768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-08","epss":0.0059,"percentile":0.46548}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/29"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84784","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-08","epss":0.00403,"percentile":0.32493}],"risk":0.30225,"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47360","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-47360","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"risk":0.2895,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-47360"},"relatedVulnerabilities":[{"id":"CVE-2026-47360","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-08","epss":0.00386,"percentile":0.30539}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/14"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n   \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"eb222fe89d397776","cpes":["cpe:2.3:a:zlib:zlib:1.3.2-r0:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.3.2-r0","language":"","licenses":["Zlib"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libz.so.1"},{"path":"/usr/lib/libz.so.1.3.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zlib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"fixed","versions":["1.3.2-r1"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.3.2-r1"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58415","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-58415","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"risk":0.274495,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-58415"},"relatedVulnerabilities":[{"id":"CVE-2026-58415","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-08","epss":0.00533,"percentile":0.43216}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/20"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v5mv-p594-2x33","versionConstraint":"<7.15.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-v5mv-p594-2x33","fix":{"state":"fixed","versions":["7.15.2"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"7.15.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69246","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-941","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69246","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"risk":0.27195,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v5mv-p594-2x33","description":"Guzzle: Noncanonical host can bypass host-based checks"},"relatedVulnerabilities":[{"id":"CVE-2026-69246","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69246","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69246","cwe":"CWE-941","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69246","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"urls":["https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1","https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69246","description":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1."}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f283-ghqc-fg79","versionConstraint":"<7.15.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-f283-ghqc-fg79","fix":{"state":"fixed","versions":["7.15.1"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67353","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67353","date":"2026-10-08","epss":0.00418,"percentile":0.34076}],"risk":0.21527,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79","https://github.com/guzzle/guzzle/pull/3901","https://github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4","https://github.com/guzzle/guzzle/releases/tag/7.15.1","https://nvd.nist.gov/vuln/detail/CVE-2026-67353","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-unbounded-cookie-denial-of-service"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f283-ghqc-fg79","description":"Guzzle: Unbounded response cookies risk denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-67353","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67353","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67353","date":"2026-10-08","epss":0.00418,"percentile":0.34076}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-f283-ghqc-fg79","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-unbounded-cookie-denial-of-service"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67353","description":"guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers."}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h95v-h523-3mw8","versionConstraint":"<7.15.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-h95v-h523-3mw8","fix":{"state":"fixed","versions":["7.15.1"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67354","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67354","date":"2026-10-08","epss":0.00372,"percentile":0.29086}],"risk":0.20274000000000003,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8","https://github.com/guzzle/guzzle/pull/3901","https://github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4","https://github.com/guzzle/guzzle/releases/tag/7.15.1","https://nvd.nist.gov/vuln/detail/CVE-2026-67354","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-uri-fragment-disclosure-via-referer"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h95v-h523-3mw8","description":"Guzzle: URI fragments disclosed in redirect Referer headers"},"relatedVulnerabilities":[{"id":"CVE-2026-67354","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67354","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67354","date":"2026-10-08","epss":0.00372,"percentile":0.29086}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-h95v-h523-3mw8","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-uri-fragment-disclosure-via-referer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67354","description":"guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value."}]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-72897","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-08","epss":0.00266,"percentile":0.1695}],"risk":0.1995,"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wm3w-8rrp-j577","versionConstraint":"<7.15.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-wm3w-8rrp-j577","fix":{"state":"fixed","versions":["7.15.1"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.15.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67355","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67355","date":"2026-10-08","epss":0.00366,"percentile":0.28387}],"risk":0.19947000000000004,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577","https://github.com/guzzle/guzzle/pull/3901","https://github.com/guzzle/guzzle/commit/7b68220d6543f6f80fe62e633361fc9d4ead14d4","https://github.com/guzzle/guzzle/releases/tag/7.15.1","https://nvd.nist.gov/vuln/detail/CVE-2026-67355","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-host-only-cookie-scope"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wm3w-8rrp-j577","description":"Guzzle: Host-only cookie scope is not preserved"},"relatedVulnerabilities":[{"id":"CVE-2026-67355","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67355","cwe":"CWE-201","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67355","date":"2026-10-08","epss":0.00366,"percentile":0.28387}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-wm3w-8rrp-j577","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-host-only-cookie-scope"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67355","description":"guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-29pj-957v-52mc","versionConstraint":">=1.5.0,<=2.8.3 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-29pj-957v-52mc","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71478","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-86","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-692","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71478","date":"2026-10-08","epss":0.00355,"percentile":0.27139}],"risk":0.19702499999999998,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc","https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-29pj-957v-52mc","description":"league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes"},"relatedVulnerabilities":[{"id":"CVE-2026-71478","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71478","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-86","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-71478","cwe":"CWE-692","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71478","date":"2026-10-08","epss":0.00355,"percentile":0.27139}],"urls":["https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c","https://github.com/thephpleague/commonmark/releases/tag/2.9.0","https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71478","description":"league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42528","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-42528","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"risk":0.19343999999999997,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-42528"},"relatedVulnerabilities":[{"id":"CVE-2026-42528","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-08","epss":0.00416,"percentile":0.33893}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/12"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.14.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-94pj-82f3-465w","versionConstraint":"<7.14.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-94pj-82f3-465w","fix":{"state":"fixed","versions":["7.14.2"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.14.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67339","cwe":"CWE-200","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67339","date":"2026-10-08","epss":0.00372,"percentile":0.29061}],"risk":0.19158,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w","https://github.com/guzzle/guzzle/pull/3876","https://github.com/guzzle/guzzle/commit/9e4580d4b9981e903dc6323fe37f50a96e85b05e","https://github.com/guzzle/guzzle/releases/tag/7.14.2","https://nvd.nist.gov/vuln/detail/CVE-2026-67339","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-proxy-authorization-header-disclosure"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-94pj-82f3-465w","description":"Guzzle: Proxy-Authorization headers can be sent to origin servers"},"relatedVulnerabilities":[{"id":"CVE-2026-67339","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-67339","cwe":"CWE-200","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-67339","date":"2026-10-08","epss":0.00372,"percentile":0.29061}],"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w","https://www.vulncheck.com/advisories/guzzlehttp-guzzle-before-proxy-authorization-header-disclosure"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-67339","description":"guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75804","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-08","epss":0.00352,"percentile":0.26759}],"risk":0.18128,"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"4395698d712dd597","cpes":["cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*"],"name":"nghttp2-libs","purl":"pkg:apk/alpine/nghttp2-libs@1.69.0-r0?arch=x86_64&distro=alpine-3.24.2&upstream=nghttp2","type":"apk","version":"1.69.0-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libnghttp2.so.14"},{"path":"/usr/lib/libnghttp2.so.14.29.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nghttp2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.70.0-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"< 1.70.0-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"nghttp2","version":"1.69.0-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"fixed","versions":["1.70.0-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"1.70.0-r0"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-58055"},"relatedVulnerabilities":[{"id":"CVE-2026-58055","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42772","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-08","epss":0.0033,"percentile":0.24031}],"risk":0.16995000000000002,"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"fef07e9c95ea2bda","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"915155597fcdee9a","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r31:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"8a9ef44e1018f213","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r31:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r31:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r31?arch=x86_64&distro=alpine-3.24.2&upstream=busybox","type":"apk","version":"1.37.0-r31","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r31"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"2c78c176e93c9919","cpes":["cpe:2.3:a:pcre2:pcre2:10.48-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre:10.48-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre2:10.48-r0:*:*:*:*:*:*:*","cpe:2.3:a:pcre:pcre:10.48-r0:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:apk/alpine/pcre2@10.48-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"10.48-r0","language":"","licenses":["BSD-3-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libpcre2-8.so.0"},{"path":"/usr/lib/libpcre2-8.so.0.16.0"},{"path":"/usr/lib/libpcre2-posix.so.3"},{"path":"/usr/lib/libpcre2-posix.so.3.0.8"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"pcre2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"10.49-r0"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"< 10.49-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"pcre2","version":"10.48-r0"},"namespace":"alpine:distro:alpine:3.24"}},{"fix":{"suggestedVersion":"10.49-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"< 10.49-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"pcre2","version":"10.48-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"fixed","versions":["10.49-r0"],"available":[{"date":"2026-10-02","kind":"first-observed","version":"10.49-r0"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"f584fae8872b6d58","cpes":["cpe:2.3:a:apache:apache2-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache2_utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache-utils:2.4.68-r0:*:*:*:*:*:*:*","cpe:2.3:a:apache:apache_utils:2.4.68-r0:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:apk/alpine/apache2-utils@2.4.68-r0?arch=x86_64&distro=alpine-3.24.2&upstream=apache2","type":"apk","version":"2.4.68-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ab"},{"path":"/usr/bin/dbmmanage"},{"path":"/usr/bin/htdbm"},{"path":"/usr/bin/htdigest"},{"path":"/usr/bin/htpasswd"},{"path":"/usr/bin/httxt2dbm"},{"path":"/usr/bin/logresolve"},{"path":"/usr/sbin"},{"path":"/usr/sbin/checkgid"},{"path":"/usr/sbin/envvars"},{"path":"/usr/sbin/envvars-std"},{"path":"/usr/sbin/htcacheclean"},{"path":"/usr/sbin/rotatelogs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"apache2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.4.69-r0"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42356","versionConstraint":"< 2.4.69-r0 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.24.2"},"package":{"name":"apache2","version":"2.4.68-r0"},"namespace":"alpine:distro:alpine:3.24"}}],"vulnerability":{"id":"CVE-2026-42356","fix":{"state":"fixed","versions":["2.4.69-r0"],"available":[{"date":"2026-10-04","kind":"first-observed","version":"2.4.69-r0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"risk":0.15745,"urls":[],"severity":"Low","namespace":"alpine:distro:alpine:3.24","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-42356"},"relatedVulnerabilities":[{"id":"CVE-2026-42356","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-08","epss":0.0047,"percentile":0.38661}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/11"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."}]},{"artifact":{"id":"23b1b1d87f1363da","cpes":["cpe:2.3:a:nginx:nginx:1.30.4-r1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:apk/alpine/nginx@1.30.4-r1?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"1.30.4-r1","language":"","licenses":["BSD-2-Clause"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/nginx"},{"path":"/etc/nginx"},{"path":"/etc/nginx/fastcgi.conf"},{"path":"/etc/nginx/fastcgi_params"},{"path":"/etc/nginx/mime.types"},{"path":"/etc/nginx/nginx.conf"},{"path":"/etc/nginx/scgi_params"},{"path":"/etc/nginx/uwsgi_params"},{"path":"/etc/nginx/http.d"},{"path":"/etc/nginx/modules"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/nginx"},{"path":"/usr/lib/nginx/modules"},{"path":"/usr/sbin"},{"path":"/usr/sbin/nginx"},{"path":"/usr/share"},{"path":"/usr/share/nginx"},{"path":"/usr/share/nginx/http-default_server.conf"},{"path":"/var"},{"path":"/var/lib"},{"path":"/var/lib/nginx"},{"path":"/var/lib/nginx/logs"},{"path":"/var/lib/nginx/modules"},{"path":"/var/lib/nginx/run"},{"path":"/var/lib/nginx/html"},{"path":"/var/lib/nginx/html/50x.html"},{"path":"/var/lib/nginx/html/index.html"},{"path":"/var/lib/nginx/tmp"},{"path":"/var/log"},{"path":"/var/log/nginx"},{"path":"/var/www"},{"path":"/var/www/localhost"},{"path":"/var/www/localhost/htdocs"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nginx"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-90439","versionConstraint":">= 1.29.2, < 1.30.0||>= 1.30.4, < 1.30.5||>= 1.31.0, < 1.31.6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.30.4:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.30.4-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-90439","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90439","cwe":"CWE-122","type":"Secondary","source":"f5sirt@f5.com"}],"epss":[{"cve":"CVE-2026-90439","date":"2026-10-08","epss":0.00256,"percentile":0.15865}],"risk":0.14976,"urls":["https://my.f5.com/manage/s/article/K000162604"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90439","description":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35189","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-08","epss":0.00267,"percentile":0.17282}],"risk":0.13750500000000002,"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-35191","versionConstraint":">= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-08","epss":0.00357,"percentile":0.27407}],"risk":0.11959499999999999,"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"8c29de47f797c6e9","cpes":["cpe:2.3:a:guzzlehttp\\/guzzle:guzzlehttp\\/guzzle:7.13.3:*:*:*:*:*:*:*"],"name":"guzzlehttp/guzzle","purl":"pkg:composer/guzzlehttp/guzzle@7.13.3","type":"php-composer","version":"7.13.3","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.15.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f7vp-7xgx-4w4r","versionConstraint":"<7.15.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"guzzlehttp/guzzle","version":"7.13.3"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-f7vp-7xgx-4w4r","fix":{"state":"fixed","versions":["7.15.2"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"7.15.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69245","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-346","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69245","date":"2026-10-08","epss":0.00199,"percentile":0.08956}],"risk":0.11442499999999999,"urls":["https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f7vp-7xgx-4w4r","description":"Guzzle: Noncanonical cookie domain keeps subdomain scope"},"relatedVulnerabilities":[{"id":"CVE-2026-69245","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69245","cwe":"CWE-180","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-346","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69245","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69245","date":"2026-10-08","epss":0.00199,"percentile":0.08956}],"urls":["https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4","https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf","https://github.com/guzzle/guzzle/pull/3907","https://github.com/guzzle/guzzle/pull/3908","https://github.com/guzzle/guzzle/releases/tag/7.15.2","https://github.com/guzzle/guzzle/releases/tag/8.0.1","https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69245","description":"Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75805","versionConstraint":">= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-08","epss":0.00222,"percentile":0.1171}],"risk":0.11433000000000001,"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"fc9c37c033fa02f1","cpes":["cpe:2.3:a:league\\/flysystem:league\\/flysystem:3.35.2:*:*:*:*:*:*:*"],"name":"league/flysystem","purl":"pkg:composer/league/flysystem@3.35.2","type":"php-composer","version":"3.35.2","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.35.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxf4-7mrp-vvpr","versionConstraint":"<=3.35.2 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/flysystem","version":"3.35.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-cxf4-7mrp-vvpr","fix":{"state":"fixed","versions":["3.35.3"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.35.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102601","cwe":"CWE-150","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102601","date":"2026-10-08","epss":0.00337,"percentile":0.25047}],"risk":0.10952499999999998,"urls":["https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr","https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77","https://github.com/thephpleague/flysystem/releases/tag/3.35.3","https://nvd.nist.gov/vuln/detail/CVE-2026-102601"],"severity":"Low","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxf4-7mrp-vvpr","description":"Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter"},"relatedVulnerabilities":[{"id":"CVE-2026-102601","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.5,"impactScore":1.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102601","cwe":"CWE-150","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102601","date":"2026-10-08","epss":0.00337,"percentile":0.25047}],"urls":["https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77","https://github.com/thephpleague/flysystem/releases/tag/3.35.3","https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102601","description":"Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return false, so paths that also contain control characters bypass CorruptedPathDetected::forPath() in normalizePath(). Filesystem::write() can store such names and Filesystem::listContents() can return the raw ANSI escape sequences, allowing hidden or spoofed terminal file listings when an administrator displays them. This issue is fixed in version 3.35.3."}]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54875","versionConstraint":">= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-08","epss":0.00294,"percentile":0.20137}],"risk":0.09849,"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54872","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-08","epss":0.00263,"percentile":0.16589}],"risk":0.08810499999999999,"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."},"relatedVulnerabilities":[]},{"artifact":{"id":"6921667c3af65467","cpes":["cpe:2.3:a:coreutils:coreutils:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.11-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"16361c4de507bb4c","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"0c43a637992609b6","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"157238390cea3b89","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.11-r0:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.11-r0:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.11-r0?arch=x86_64&distro=alpine-3.24.2&upstream=coreutils","type":"apk","version":"9.11-r0","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56392","versionConstraint":"= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.11:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.11-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56392","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56392","cwe":"CWE-122","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56392","date":"2026-10-08","epss":0.00186,"percentile":0.07525}],"risk":0.083235,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56392","description":"GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer.\nWhen processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.\n\nWhen running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.\n\n\n\n\n\n\n\n\n\n\nThis issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d"},"relatedVulnerabilities":[]},{"artifact":{"id":"c1fed726b9e0ccb7","cpes":["cpe:2.3:a:libcrypto3:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto3:libcrypto:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libcrypto:libcrypto:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libcrypto3","purl":"pkg:apk/alpine/libcrypto3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/ssl"},{"path":"/etc/ssl/ct_log_list.cnf"},{"path":"/etc/ssl/ct_log_list.cnf.dist"},{"path":"/etc/ssl/openssl.cnf"},{"path":"/etc/ssl/openssl.cnf.dist"},{"path":"/etc/ssl/certs"},{"path":"/etc/ssl/private"},{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libcrypto.so.3"},{"path":"/usr/lib/engines-3"},{"path":"/usr/lib/engines-3/afalg.so"},{"path":"/usr/lib/engines-3/capi.so"},{"path":"/usr/lib/engines-3/loader_attic.so"},{"path":"/usr/lib/engines-3/padlock.so"},{"path":"/usr/lib/ossl-modules"},{"path":"/usr/lib/ossl-modules/legacy.so"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"269544be9368a131","cpes":["cpe:2.3:a:libssl3:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl3:libssl:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl3:3.5.8-r0:*:*:*:*:*:*:*","cpe:2.3:a:libssl:libssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"libssl3","purl":"pkg:apk/alpine/libssl3@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2&upstream=openssl","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libssl.so.3"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"c2e703af3647d000","cpes":["cpe:2.3:a:openssl:openssl:3.5.8-r0:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:apk/alpine/openssl@3.5.8-r0?arch=x86_64&distro=alpine-3.24.2","type":"apk","version":"3.5.8-r0","language":"","licenses":["Apache-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/openssl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-77696","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.5.8:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.5.8-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-77696","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77696","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-77696","date":"2026-10-08","epss":0.00243,"percentile":0.14252}],"risk":0.08140499999999999,"urls":["https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9","https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb","https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64","https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696","description":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm."},"relatedVulnerabilities":[]},{"artifact":{"id":"22cc25b71164504a","cpes":["cpe:2.3:a:laravel\\/framework:laravel\\/framework:v13.19.0:*:*:*:*:*:*:*"],"name":"laravel/framework","purl":"pkg:composer/laravel/framework@v13.19.0","type":"php-composer","version":"v13.19.0","language":"php","licenses":["MIT"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"13.30.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jh5r-qr3c-85q8","versionConstraint":">=13.0.0,<13.30.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"laravel/framework","version":"v13.19.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-jh5r-qr3c-85q8","fix":{"state":"fixed","versions":["13.30.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"13.30.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102279","cwe":"CWE-80","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102279","date":"2026-10-08","epss":0.00202,"percentile":0.09236}],"risk":0.061610000000000005,"urls":["https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8","https://nvd.nist.gov/vuln/detail/CVE-2026-102279","https://github.com/laravel/framework/pull/61381","https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12","https://github.com/laravel/framework/releases/tag/v12.69.0","https://github.com/laravel/framework/releases/tag/v13.30.0"],"severity":"Low","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jh5r-qr3c-85q8","description":"Laravel: XSS in Debug Page Information"},"relatedVulnerabilities":[{"id":"CVE-2026-102279","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102279","cwe":"CWE-80","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102279","date":"2026-10-08","epss":0.00202,"percentile":0.09236}],"urls":["https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12","https://github.com/laravel/framework/pull/61381","https://github.com/laravel/framework/releases/tag/v12.69.0","https://github.com/laravel/framework/releases/tag/v13.30.0","https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102279","description":"Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scripting when a user hovers over the tooltip. This issue is fixed in versions 12.69.0 and 13.30.0."}]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.10.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3q6v-r5mr-hxv8","versionConstraint":">=2.0.0,<=2.10.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-3q6v-r5mr-hxv8","fix":{"state":"fixed","versions":["2.10.2"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-3q6v-r5mr-hxv8","https://github.com/thephpleague/commonmark/commit/5f63680a5e29dd57f9c6be9743b0e90493d3c2d0","https://github.com/thephpleague/commonmark/releases/tag/2.10.2"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3q6v-r5mr-hxv8","description":"league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.10.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8rr7-cvq3-gmfh","versionConstraint":">=1.5.0,<2.10.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-8rr7-cvq3-gmfh","fix":{"state":"fixed","versions":["2.10.0"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.10.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-8rr7-cvq3-gmfh","https://github.com/thephpleague/commonmark/commit/f27eb720972490b5af4dbb635ad8634529faf9f2","https://github.com/thephpleague/commonmark/releases/tag/2.10.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8rr7-cvq3-gmfh","description":"league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f8fg-pg57-v4j8","versionConstraint":">=2.7.0,<2.9.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-f8fg-pg57-v4j8","fix":{"state":"fixed","versions":["2.9.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":7.2,"impactScore":2.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-f8fg-pg57-v4j8","https://github.com/thephpleague/commonmark/commit/dfcdf4554c16aa37c15e3a5ee3243ee26147c239","https://github.com/thephpleague/commonmark/releases/tag/2.9.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f8fg-pg57-v4j8","description":"league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g2gp-3wwq-f4ph","versionConstraint":">=1.5.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-g2gp-3wwq-f4ph","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-g2gp-3wwq-f4ph","https://github.com/thephpleague/commonmark/commit/2d4c0fafa62501be919262064cffa6d71687430b","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g2gp-3wwq-f4ph","description":"league/commonmark: Denial of service via adjacent inline attribute blocks"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j8pm-gj4c-rq4x","versionConstraint":">=0.6.0,<2.9.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-j8pm-gj4c-rq4x","fix":{"state":"fixed","versions":["2.9.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-j8pm-gj4c-rq4x","https://github.com/thephpleague/commonmark/commit/0768217751fbfaeb8d76762f6944e9af7114295e","https://github.com/thephpleague/commonmark/commit/d9375fadc308a63a02950a68d822417a6e4c33b2","https://github.com/thephpleague/commonmark/commit/e0036ef031fd36ec1c3c82db8743fc928b5271c8","https://github.com/thephpleague/commonmark/releases/tag/2.9.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j8pm-gj4c-rq4x","description":"league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jfm3-95jq-q3rf","versionConstraint":">=1.5.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-jfm3-95jq-q3rf","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-jfm3-95jq-q3rf","https://github.com/thephpleague/commonmark/commit/66028124a17ba193da7b11cc3dfda92df21bfbf4","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jfm3-95jq-q3rf","description":"league/commonmark:  Denial of service via duplicate footnote definitions"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jjv6-8j6v-6j52","versionConstraint":">=1.5.0,<2.9.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-jjv6-8j6v-6j52","fix":{"state":"fixed","versions":["2.9.1"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"2.9.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-jjv6-8j6v-6j52","https://github.com/thephpleague/commonmark/commit/04a5d11ef6bf2d0b927310810d6a2a85d3c184b9","https://github.com/thephpleague/commonmark/commit/2f611b599c51661b005dc45c16ceaa547546e687","https://github.com/thephpleague/commonmark/releases/tag/2.9.1"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jjv6-8j6v-6j52","description":"league/commonmark: Denial of service in the SmartPunct and Attributes extensions"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mh25-x5hq-wrqp","versionConstraint":">=2.0.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-mh25-x5hq-wrqp","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-mh25-x5hq-wrqp","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"High","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mh25-x5hq-wrqp","description":"league/commonmark: Denial of service via colliding heading slugs"},"relatedVulnerabilities":[]},{"artifact":{"id":"a7e1137fdae96eff","cpes":["cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*"],"name":"enshrined/svg-sanitize","purl":"pkg:composer/enshrined/svg-sanitize@0.22.0","type":"php-composer","version":"0.22.0","language":"php","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9rjx-3jch-6vjf","versionConstraint":"<=0.22.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"enshrined/svg-sanitize","version":"0.22.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-9rjx-3jch-6vjf","fix":{"state":"fixed","versions":["1.0.0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107380","cwe":"CWE-79","type":"Primary","source":"security-advisories@github.com"}],"risk":0,"urls":["https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf","https://nvd.nist.gov/vuln/detail/CVE-2026-107380","https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9rjx-3jch-6vjf","description":"enshrined/svg-sanitize: Stored XSS via DTD Entity / HTML5 Named Character Reference Collision"},"relatedVulnerabilities":[{"id":"CVE-2026-107380","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107380","cwe":"CWE-79","type":"Primary","source":"security-advisories@github.com"}],"urls":["https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0","https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-9rjx-3jch-6vjf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107380","description":"savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer's isHrefSafeValue() validates an SVG href after XML DTD entity expansion, but saveXML() serializes the original entity reference after removing the DTD declaration. A crafted entity such as Tab can appear to the sanitizer as a safe fragment prefix while HTML5 Named Character Reference resolution during inline HTML rendering later converts the surviving reference to whitespace, exposing a javascript: URL. When an application embeds the sanitized SVG inline, a user who activates the link can cause script to execute in the embedding page's origin. This issue is fixed in version 1.0.0."}]},{"artifact":{"id":"a7e1137fdae96eff","cpes":["cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*"],"name":"enshrined/svg-sanitize","purl":"pkg:composer/enshrined/svg-sanitize@0.22.0","type":"php-composer","version":"0.22.0","language":"php","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m9xh-6747-9r6f","versionConstraint":"<=0.22.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"enshrined/svg-sanitize","version":"0.22.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-m9xh-6747-9r6f","fix":{"state":"fixed","versions":["1.0.0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-m9xh-6747-9r6f","https://github.com/darylldoyle/svg-sanitizer/commit/2dff6628314de8519155b7feb218bbe132785757","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m9xh-6747-9r6f","description":"svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences"},"relatedVulnerabilities":[{"id":"CVE-2026-107381","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"a7e1137fdae96eff","cpes":["cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg-sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg_sanitize:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg-sanitize:0.22.0:*:*:*:*:*:*:*","cpe:2.3:a:enshrined\\/svg:enshrined\\/svg_sanitize:0.22.0:*:*:*:*:*:*:*"],"name":"enshrined/svg-sanitize","purl":"pkg:composer/enshrined/svg-sanitize@0.22.0","type":"php-composer","version":"0.22.0","language":"php","licenses":["GPL-2.0-or-later"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v383-3rw5-q8rf","versionConstraint":"<=0.22.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"enshrined/svg-sanitize","version":"0.22.0"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-v383-3rw5-q8rf","fix":{"state":"fixed","versions":["1.0.0"],"available":[{"date":"2026-10-09","kind":"first-observed","version":"1.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107379","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"risk":0,"urls":["https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-v383-3rw5-q8rf","https://nvd.nist.gov/vuln/detail/CVE-2026-107379","https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v383-3rw5-q8rf","description":"enshrined/svg-sanitize: Denial of Service via DTD Attribute Declaration Crash"},"relatedVulnerabilities":[{"id":"CVE-2026-107379","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-107379","cwe":"CWE-770","type":"Primary","source":"security-advisories@github.com"}],"urls":["https://github.com/darylldoyle/svg-sanitizer/commit/23877db7e76f1e1df5c3e65ab30239219c3d2867","https://github.com/darylldoyle/svg-sanitizer/releases/tag/1.0.0","https://github.com/darylldoyle/svg-sanitizer/security/advisories/GHSA-v383-3rw5-q8rf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-107379","description":"savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, svg-sanitizer allows a crafted SVG DTD with a #FIXED attribute default to make cleanAttributesOnWhitelist() perform a double DOMElement::removeAttribute() call on the same attribute name in src/Sanitizer.php. The first removal deletes the explicit attribute, while the DTD default rematerializes the value before the href safety path performs the second removal, which can corrupt libxml state and terminate the PHP worker. An attacker who can submit SVG content to a sanitization endpoint can repeatedly interrupt workers and degrade or exhaust application availability. This issue is fixed in version 1.0.0."}]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.10.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-97jj-33gv-5xf9","versionConstraint":">=1.3.0,<=2.10.1 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-97jj-33gv-5xf9","fix":{"state":"fixed","versions":["2.10.2"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-97jj-33gv-5xf9","https://github.com/thephpleague/commonmark/commit/411afcc2a7402756d96c89af8882c724d12d47ca","https://github.com/thephpleague/commonmark/releases/tag/2.10.2"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-97jj-33gv-5xf9","description":"league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal"},"relatedVulnerabilities":[]},{"artifact":{"id":"e964e2f6e76929df","cpes":["cpe:2.3:a:league\\/commonmark:league\\/commonmark:2.8.2:*:*:*:*:*:*:*"],"name":"league/commonmark","purl":"pkg:composer/league/commonmark@2.8.2","type":"php-composer","version":"2.8.2","language":"php","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/www-tmp/vendor/composer/installed.json","layerID":"sha256:601dafbf57e80a65d2097ca57a7c5c179c398d345cf6cf8f0867fba34b02e2bf","accessPath":"/app/www-tmp/vendor/composer/installed.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.9.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mj63-m3rc-8ppr","versionConstraint":">=2.0.0,<2.9.0 (semantic)"},"matcher":"stock-matcher","searchedBy":{"package":{"name":"league/commonmark","version":"2.8.2"},"language":"php","namespace":"github:language:php"}}],"vulnerability":{"id":"GHSA-mj63-m3rc-8ppr","fix":{"state":"fixed","versions":["2.9.0"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"2.9.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"risk":0,"urls":["https://github.com/thephpleague/commonmark/security/advisories/GHSA-mj63-m3rc-8ppr","https://github.com/thephpleague/commonmark/commit/b5ac8c3947ca81844e85a09c7e0a5b4148bde2e1","https://github.com/thephpleague/commonmark/releases/tag/2.9.0"],"severity":"Medium","namespace":"github:language:php","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mj63-m3rc-8ppr","description":"league/commonmark: Denial of service via deeply nested XML output"},"relatedVulnerabilities":[]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:19:00.636Z","grype_db_version":"2026-10-09T06:32:32.000Z"}