{"grype_matches":[{"artifact":{"id":"2fd8ac9813678144","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.26.0-19.el8_9?arch=x86_64&distro=rhel-8.10&upstream=sqlite-3.26.0-19.el8_9.src.rpm","type":"rpm","version":"3.26.0-19.el8_9","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.26.0-19.el8_9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.26.0-20.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6965","versionConstraint":"< 0:3.26.0-20.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"sqlite","version":"3.26.0-19.el8_9"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6965","fix":{"state":"fixed","versions":["0:3.26.0-20.el8_10"],"available":[{"date":"2025-07-30","kind":"first-observed","version":"0:3.26.0-20.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.3,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"risk":54.259440000000005,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:12010","link":"https://access.redhat.com/errata/RHSA-2025:12010"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6965","description":"A memory corruption flaw was found in SQLite. Under specific conditions a query can be generated where the number of aggregate terms could exceed the number of columns available. This issue could lead to memory corruption and subsequent unintended behavior."},"relatedVulnerabilities":[{"id":"CVE-2025-6965","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.3,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve-coordination@google.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6965","cwe":"CWE-197","type":"Secondary","source":"cve-coordination@google.com"}],"epss":[{"cve":"CVE-2025-6965","date":"2026-10-08","epss":0.71394,"percentile":0.99401}],"urls":["https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8","http://seclists.org/fulldisclosure/2025/Sep/49","http://seclists.org/fulldisclosure/2025/Sep/53","http://seclists.org/fulldisclosure/2025/Sep/56","http://seclists.org/fulldisclosure/2025/Sep/57","http://seclists.org/fulldisclosure/2025/Sep/58","http://www.openwall.com/lists/oss-security/2025/09/06/1","https://cert-portal.siemens.com/productcert/html/ssa-225816.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6965","description":"There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.15"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-6119","versionConstraint":">= 3.0.0, < 3.0.15||>= 3.1.0, < 3.1.7||>= 3.2.0, < 3.2.3||>= 3.3.0, < 3.3.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-6119","fix":{"state":"fixed","versions":["3.0.15","3.1.7","3.2.3","3.3.2"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"3.0.15"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.7"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.3"},{"date":"2025-09-04","kind":"first-observed","version":"3.3.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-6119","cwe":"CWE-843","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6119","date":"2026-10-08","epss":0.66582,"percentile":0.99272}],"risk":49.936499999999995,"urls":["https://github.com/openssl/openssl/commit/05f360d9e849a1b277db628f1f13083a7f8dd04f","https://github.com/openssl/openssl/commit/06d1dc3fa96a2ba5a3e22735a033012aadc9f0d6","https://github.com/openssl/openssl/commit/621f3729831b05ee828a3203eddb621d014ff2b2","https://github.com/openssl/openssl/commit/7dfcee2cd2a63b2c64b9b4b0850be64cb695b0a0","https://openssl-library.org/news/secadv/20240903.txt","http://www.openwall.com/lists/oss-security/2024/09/03/4","https://lists.freebsd.org/archives/freebsd-security/2024-September/000303.html","https://security.netapp.com/advisory/ntap-20240912-0001/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6119","description":"Issue summary: Applications performing certificate name checks (e.g., TLS\nclients checking server certificates) may attempt to read an invalid memory\naddress resulting in abnormal termination of the application process.\n\nImpact summary: Abnormal termination of an application can a cause a denial of\nservice.\n\nApplications performing certificate name checks (e.g., TLS clients checking\nserver certificates) may attempt to read an invalid memory address when\ncomparing the expected name with an `otherName` subject alternative name of an\nX.509 certificate. This may result in an exception that terminates the\napplication program.\n\nNote that basic certificate chain validation (signatures, dates, ...) is not\naffected, the denial of service can occur only when the application also\nspecifies an expected DNS name, Email address or IP address.\n\nTLS servers rarely solicit client certificates, and even when they do, they\ngenerally don't perform a name check against a reference identifier (expected\nidentity), but rather extract the presented identity after checking the\ncertificate chain.  So TLS servers are generally not affected and the severity\nof the issue is Moderate.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.19"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15467","versionConstraint":">= 3.0.0, < 3.0.19||>= 3.3.0, < 3.3.6||>= 3.4.0, < 3.4.4||>= 3.5.0, < 3.5.5||>= 3.6.0, < 3.6.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15467","fix":{"state":"fixed","versions":["3.0.19","3.3.6","3.4.4","3.5.5","3.6.1"],"available":[{"date":"2026-01-29","kind":"first-observed","version":"3.0.19"},{"date":"2026-01-29","kind":"first-observed","version":"3.3.6"},{"date":"2026-01-29","kind":"first-observed","version":"3.4.4"},{"date":"2026-01-29","kind":"first-observed","version":"3.5.5"},{"date":"2026-01-29","kind":"first-observed","version":"3.6.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15467","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-15467","cwe":"CWE-120","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-15467","date":"2026-10-08","epss":0.52446,"percentile":0.98938}],"risk":47.98809000000001,"urls":["https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703","https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9","https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3","https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e","https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc","https://openssl-library.org/news/secadv/20260127.txt","http://www.openwall.com/lists/oss-security/2026/01/27/10","http://www.openwall.com/lists/oss-security/2026/02/25/6","https://access.redhat.com/errata/RHSA-2026:1472","https://access.redhat.com/errata/RHSA-2026:1473","https://access.redhat.com/errata/RHSA-2026:1496","https://access.redhat.com/errata/RHSA-2026:1503","https://access.redhat.com/errata/RHSA-2026:1519","https://access.redhat.com/errata/RHSA-2026:1594","https://access.redhat.com/errata/RHSA-2026:1733","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:2072","https://access.redhat.com/errata/RHSA-2026:2077","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2633","https://access.redhat.com/errata/RHSA-2026:2659","https://access.redhat.com/errata/RHSA-2026:2671","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:2974","https://access.redhat.com/errata/RHSA-2026:2995","https://access.redhat.com/errata/RHSA-2026:3228","https://access.redhat.com/errata/RHSA-2026:3415","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:4419","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:6481","https://access.redhat.com/errata/RHSA-2026:7261","https://access.redhat.com/security/cve/CVE-2025-15467","https://bugzilla.redhat.com/show_bug.cgi?id=2430376","https://cert-portal.siemens.com/productcert/html/ssa-434797.html","https://cert-portal.siemens.com/productcert/html/ssa-734552.html","https://github.com/guiimoraes/CVE-2025-15467","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15467","description":"Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-2650","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-2650","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"risk":43.1917,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-2650","description":"A flaw was found in OpenSSL resulting in a possible denial of service while translating ASN.1 object identifiers. Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience long delays when processing messages, which may lead to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-2650","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-2650","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-2650","date":"2026-10-08","epss":0.75116,"percentile":0.995}],"urls":["http://www.openwall.com/lists/oss-security/2023/05/30/1","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=423a2bc737a908ad0c77bda470b2b59dc879936b","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=853c5e56ee0b8650c73140816bb8b91d6163422c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9e209944b35cf82368071f160a744b6178f9b098","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db779b0e10b047f2585615e0b8f2acdf21f8544a","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0009","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230703-0001/","https://security.netapp.com/advisory/ntap-20231027-0009/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230530.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2650","description":"Issue summary: Processing some specially crafted ASN.1 object identifiers or\ndata containing them may be very slow.\n\nImpact summary: Applications that use OBJ_obj2txt() directly, or use any of\nthe OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message\nsize limit may experience notable to very long delays when processing those\nmessages, which may lead to a Denial of Service.\n\nAn OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers -\nmost of which have no size limit.  OBJ_obj2txt() may be used to translate\nan ASN.1 OBJECT IDENTIFIER given in DER encoding form (using the OpenSSL\ntype ASN1_OBJECT) to its canonical numeric text form, which are the\nsub-identifiers of the OBJECT IDENTIFIER in decimal form, separated by\nperiods.\n\nWhen one of the sub-identifiers in the OBJECT IDENTIFIER is very large\n(these are sizes that are seen as absurdly large, taking up tens or hundreds\nof KiBs), the translation to a decimal number in text may take a very long\ntime.  The time complexity is O(n^2) with 'n' being the size of the\nsub-identifiers in bytes (*).\n\nWith OpenSSL 3.0, support to fetch cryptographic algorithms using names /\nidentifiers in string form was introduced.  This includes using OBJECT\nIDENTIFIERs in canonical numeric text form as identifiers for fetching\nalgorithms.\n\nSuch OBJECT IDENTIFIERs may be received through the ASN.1 structure\nAlgorithmIdentifier, which is commonly used in multiple protocols to specify\nwhat cryptographic algorithm should be used to sign or verify, encrypt or\ndecrypt, or digest passed data.\n\nApplications that call OBJ_obj2txt() directly with untrusted data are\naffected, with any version of OpenSSL.  If the use is for the mere purpose\nof display, the severity is considered low.\n\nIn OpenSSL 3.0 and newer, this affects the subsystems OCSP, PKCS7/SMIME,\nCMS, CMP/CRMF or TS.  It also impacts anything that processes X.509\ncertificates, including simple things like verifying its signature.\n\nThe impact on TLS is relatively low, because all versions of OpenSSL have a\n100KiB limit on the peer's certificate chain.  Additionally, this only\nimpacts clients, or servers that have explicitly enabled client\nauthentication.\n\nIn OpenSSL 1.1.1 and 1.0.2, this only affects displaying diverse objects,\nsuch as X.509 certificates.  This is assumed to not happen in such a way\nthat it would cause a Denial of Service, so these versions are considered\nnot affected by this issue in such a way that it would be cause for concern,\nand the severity is therefore considered low."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.14"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-2511","versionConstraint":">= 1.1.1, < 1.1.1y||>= 3.0.0, < 3.0.14||>= 3.1.0, < 3.1.6||>= 3.2.0, < 3.2.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-2511","fix":{"state":"fixed","versions":["1.1.1y","3.0.14","3.1.6","3.2.2"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.1.1y"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.14"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.6"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"risk":28.569444999999998,"urls":["https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640","https://www.openssl.org/news/secadv/20240408.txt","http://www.openwall.com/lists/oss-security/2024/04/08/5","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240503-0013/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-354112.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2511","description":"Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-2511","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-2511","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"risk":17.561034999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-2511","description":"A flaw was found in OpenSSL. A malicious client can trigger an uncontrolled memory consumption, resulting in a Denial of Service. This issue occurs due to OpenSSL's TLSv1.3 session cache going into an incorrect state, leading to it failing to flush properly as it fills. OpenSSL must be configured with the non-default SSL_OP_NO_TICKET option enabled to be vulnerable. This issue only affects TLSv1.3 servers, while TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2024-2511","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2511","cwe":"CWE-1325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-2511","date":"2026-10-08","epss":0.52421,"percentile":0.98938}],"urls":["https://github.com/openssl/openssl/commit/7e4d731b1c07201ad9374c1cd9ac5263bdf35bce","https://github.com/openssl/openssl/commit/b52867a9f618bb955bed2a3ce3db4d4f97ed8e5d","https://github.com/openssl/openssl/commit/e9d7083e241670332e0443da0f0d4ffb52829f08","https://github.openssl.org/openssl/extended-releases/commit/5f8d25770ae6437db119dfc951e207271a326640","https://www.openssl.org/news/secadv/20240408.txt","http://www.openwall.com/lists/oss-security/2024/04/08/5","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240503-0013/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-354112.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2511","description":"Issue summary: Some non-default TLS server configurations can cause unbounded\nmemory growth when processing TLSv1.3 sessions\n\nImpact summary: An attacker may exploit certain server configurations to trigger\nunbounded memory growth that would lead to a Denial of Service\n\nThis problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is\nbeing used (but not if early_data support is also configured and the default\nanti-replay protection is in use). In this case, under certain conditions, the\nsession cache can get into an incorrect state and it will fail to flush properly\nas it fills. The session cache will continue to grow in an unbounded manner. A\nmalicious client could deliberately create the scenario for this failure to\nforce a Denial of Service. It may also happen by accident in normal operation.\n\nThis issue only affects TLS servers supporting TLSv1.3. It does not affect TLS\nclients.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL\n1.0.2 is also not affected by this issue."}]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-1.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2013-0340","versionConstraint":"< 0:2.5.0-1.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2013-0340","fix":{"state":"fixed","versions":["0:2.5.0-1.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.5.0-1.el8_10"}]},"cvss":[],"cwes":[{"cve":"CVE-2013-0340","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2013-0340","date":"2026-10-08","epss":0.19433,"percentile":0.97303}],"risk":9.7165,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:21776","link":"https://access.redhat.com/errata/RHSA-2025:21776"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2013-0340","description":"expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.  NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE."},"relatedVulnerabilities":[{"id":"CVE-2013-0340","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2013-0340","cwe":"CWE-611","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2013-0340","date":"2026-10-08","epss":0.19433,"percentile":0.97303}],"urls":["http://openwall.com/lists/oss-security/2013/02/22/3","http://seclists.org/fulldisclosure/2021/Oct/61","http://seclists.org/fulldisclosure/2021/Oct/62","http://seclists.org/fulldisclosure/2021/Oct/63","http://seclists.org/fulldisclosure/2021/Sep/33","http://seclists.org/fulldisclosure/2021/Sep/34","http://seclists.org/fulldisclosure/2021/Sep/35","http://seclists.org/fulldisclosure/2021/Sep/38","http://seclists.org/fulldisclosure/2021/Sep/39","http://seclists.org/fulldisclosure/2021/Sep/40","http://securitytracker.com/id?1028213","http://www.openwall.com/lists/oss-security/2013/04/12/6","http://www.openwall.com/lists/oss-security/2021/10/07/4","http://www.osvdb.org/90634","http://www.securityfocus.com/bid/58233","https://github.com/libexpat/libexpat/blob/R_2_4_1/expat/Changes","https://lists.apache.org/thread.html/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702%40%3Cusers.openoffice.apache.org%3E","https://security.gentoo.org/glsa/201701-21","https://support.apple.com/kb/HT212804","https://support.apple.com/kb/HT212805","https://support.apple.com/kb/HT212807","https://support.apple.com/kb/HT212814","https://support.apple.com/kb/HT212815","https://support.apple.com/kb/HT212819"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2013-0340","description":"expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue.  NOTE: it could be argued that because expat already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed, and each affected application would need its own CVE."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":7.179915,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7264","description":"A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated."},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7264","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-7264","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"risk":7.179915,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7264","description":"A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the length of the *time fraction*, leading to a `strlen()` performed on a pointer to a heap buffer area that is not purposely NULL terminated."},"relatedVulnerabilities":[{"id":"CVE-2024-7264","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7264","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7264","date":"2026-10-08","epss":0.17301,"percentile":0.9704}],"urls":["http://www.openwall.com/lists/oss-security/2024/07/31/1","https://curl.se/docs/CVE-2024-7264.html","https://curl.se/docs/CVE-2024-7264.json","https://hackerone.com/reports/2629968","https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519","https://security.netapp.com/advisory/ntap-20240828-0008/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7264","description":"libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an\nASN.1 Generalized Time field. If given an syntactically incorrect field, the\nparser might end up using -1 for the length of the *time fraction*, leading to\na `strlen()` getting performed on a pointer to a heap buffer area that is not\n(purposely) null terminated.\n\nThis flaw most likely leads to a crash, but can also lead to heap contents\ngetting returned to the application when\n[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used."}]},{"artifact":{"id":"3a9e7d2273c9bbfb","cpes":["cpe:2.3:a:lz4-libs:lz4-libs:1.8.3-3.el8_4:*:*:*:*:*:*:*","cpe:2.3:a:lz4-libs:lz4_libs:1.8.3-3.el8_4:*:*:*:*:*:*:*","cpe:2.3:a:lz4_libs:lz4-libs:1.8.3-3.el8_4:*:*:*:*:*:*:*","cpe:2.3:a:lz4_libs:lz4_libs:1.8.3-3.el8_4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:lz4-libs:1.8.3-3.el8_4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:lz4_libs:1.8.3-3.el8_4:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-libs:1.8.3-3.el8_4:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_libs:1.8.3-3.el8_4:*:*:*:*:*:*:*"],"name":"lz4-libs","purl":"pkg:rpm/redhat/lz4-libs@1.8.3-3.el8_4?arch=x86_64&distro=rhel-8.10&upstream=lz4-1.8.3-3.el8_4.src.rpm","type":"rpm","version":"1.8.3-3.el8_4","language":"","licenses":["GPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"lz4","version":"1.8.3-3.el8_4"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.8.3-5.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-17543","versionConstraint":"< 0:1.8.3-5.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"lz4","version":"1.8.3-3.el8_4"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-17543","fix":{"state":"fixed","versions":["0:1.8.3-5.el8_10"],"available":[{"date":"2025-07-16","kind":"first-observed","version":"0:1.8.3-5.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17543","date":"2026-10-08","epss":0.09116,"percentile":0.95192}],"risk":5.970980000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:11035","link":"https://access.redhat.com/errata/RHSA-2025:11035"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-17543","description":"LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states \"only a few specific / uncommon usages of the API are at risk.\""},"relatedVulnerabilities":[{"id":"CVE-2019-17543","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-17543","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-17543","date":"2026-10-08","epss":0.09116,"percentile":0.95192}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00069.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00070.html","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=15941","https://github.com/lz4/lz4/compare/v1.9.1...v1.9.2","https://github.com/lz4/lz4/issues/801","https://github.com/lz4/lz4/pull/756","https://github.com/lz4/lz4/pull/760","https://lists.apache.org/thread.html/25015588b770d67470b7ba7ea49a305d6735dd7f00eabe7d50ec1e17%40%3Cissues.arrow.apache.org%3E","https://lists.apache.org/thread.html/543302d55e2d2da4311994e9b0debdc676bf3fd05e1a2be3407aa2d6%40%3Cissues.arrow.apache.org%3E","https://lists.apache.org/thread.html/793012683dc0fa6819b7c2560e6cf990811014c40c7d75412099c357%40%3Cissues.arrow.apache.org%3E","https://lists.apache.org/thread.html/9ff0606d16be2ab6a81619e1c9e23c3e251756638e36272c8c8b7fa3%40%3Cissues.arrow.apache.org%3E","https://lists.apache.org/thread.html/f0038c4fab2ee25aee849ebeff6b33b3aa89e07ccfb06b5c87b36316%40%3Cissues.arrow.apache.org%3E","https://lists.apache.org/thread.html/f506bc371d4a068d5d84d7361293568f61167d3a1c3e91f0def2d7d3%40%3Cdev.arrow.apache.org%3E","https://lists.apache.org/thread.html/r0fb226357e7988a241b06b93bab065bcea2eb38658b382e485960e26%40%3Cissues.kudu.apache.org%3E","https://lists.apache.org/thread.html/r4068ba81066792f2b4d208b39c4c4713c5d4c79bd8cb6c1904af5720%40%3Cissues.kudu.apache.org%3E","https://lists.apache.org/thread.html/r7bc72200f94298bc9a0e35637f388deb53467ca4b2e2ad1ff66d8960%40%3Cissues.kudu.apache.org%3E","https://security.netapp.com/advisory/ntap-20210723-0001/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-17543","description":"LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the vendor states \"only a few specific / uncommon usages of the API are at risk.\""}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.15"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-5535","versionConstraint":">= 1.0.2, < 1.0.2zk||>= 1.1.1, < 1.1.1za||>= 3.0.0, < 3.0.15||>= 3.1.0, < 3.1.7||>= 3.2.0, < 3.2.3||>= 3.3.0, < 3.3.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-5535","fix":{"state":"fixed","versions":["1.0.2zk","1.1.1za","3.0.15","3.1.7","3.2.3","3.3.2"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.0.2zk"},{"date":"2025-09-04","kind":"first-observed","version":"1.1.1za"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.15"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.7"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.3"},{"date":"2025-09-04","kind":"first-observed","version":"3.3.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-5535","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-5535","date":"2026-10-08","epss":0.05582,"percentile":0.92684}],"risk":5.05171,"urls":["https://github.com/openssl/openssl/commit/4ada436a1946cbb24db5ab4ca082b69c1bc10f37","https://github.com/openssl/openssl/commit/99fb785a5f85315b95288921a321a935ea29a51e","https://github.com/openssl/openssl/commit/cf6f91f6121f4db167405db2f0de410a456f260c","https://github.com/openssl/openssl/commit/e86ac436f0bd54d4517745483e2315650fae7b2c","https://github.openssl.org/openssl/extended-releases/commit/9947251413065a05189a63c9b7a6c1d4e224c21c","https://github.openssl.org/openssl/extended-releases/commit/b78ec0824da857223486660177d3b1f255c65d87","https://www.openssl.org/news/secadv/20240627.txt","http://www.openwall.com/lists/oss-security/2024/06/27/1","http://www.openwall.com/lists/oss-security/2024/06/28/4","http://www.openwall.com/lists/oss-security/2024/08/15/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240712-0005/","https://security.netapp.com/advisory/ntap-20241025-0006/","https://security.netapp.com/advisory/ntap-20241025-0010/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-5535","description":"Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an\nempty supported client protocols buffer may cause a crash or memory contents to\nbe sent to the peer.\n\nImpact summary: A buffer overread can have a range of potential consequences\nsuch as unexpected application beahviour or a crash. In particular this issue\ncould result in up to 255 bytes of arbitrary private data from memory being sent\nto the peer leading to a loss of confidentiality. However, only applications\nthat directly call the SSL_select_next_proto function with a 0 length list of\nsupported client protocols are affected by this issue. This would normally never\nbe a valid scenario and is typically not under attacker control but may occur by\naccident in the case of a configuration or programming error in the calling\napplication.\n\nThe OpenSSL API function SSL_select_next_proto is typically used by TLS\napplications that support ALPN (Application Layer Protocol Negotiation) or NPN\n(Next Protocol Negotiation). NPN is older, was never standardised and\nis deprecated in favour of ALPN. We believe that ALPN is significantly more\nwidely deployed than NPN. The SSL_select_next_proto function accepts a list of\nprotocols from the server and a list of protocols from the client and returns\nthe first protocol that appears in the server list that also appears in the\nclient list. In the case of no overlap between the two lists it returns the\nfirst item in the client list. In either case it will signal whether an overlap\nbetween the two lists was found. In the case where SSL_select_next_proto is\ncalled with a zero length client list it fails to notice this condition and\nreturns the memory immediately following the client list pointer (and reports\nthat there was no overlap in the lists).\n\nThis function is typically called from a server side application callback for\nALPN or a client side application callback for NPN. In the case of ALPN the list\nof protocols supplied by the client is guaranteed by libssl to never be zero in\nlength. The list of server protocols comes from the application and should never\nnormally be expected to be of zero length. In this case if the\nSSL_select_next_proto function has been called as expected (with the list\nsupplied by the client passed in the client/client_len parameters), then the\napplication will not be vulnerable to this issue. If the application has\naccidentally been configured with a zero length server list, and has\naccidentally passed that zero length server list in the client/client_len\nparameters, and has additionally failed to correctly handle a \"no overlap\"\nresponse (which would normally result in a handshake failure in ALPN) then it\nwill be vulnerable to this problem.\n\nIn the case of NPN, the protocol permits the client to opportunistically select\na protocol when there is no overlap. OpenSSL returns the first client protocol\nin the no overlap case in support of this. The list of client protocols comes\nfrom the application and should never normally be expected to be of zero length.\nHowever if the SSL_select_next_proto function is accidentally called with a\nclient_len of 0 then an invalid memory pointer will be returned instead. If the\napplication uses this output as the opportunistic protocol then the loss of\nconfidentiality will occur.\n\nThis issue has been assessed as Low severity because applications are most\nlikely to be vulnerable if they are using NPN instead of ALPN - but NPN is not\nwidely used. It also requires an application configuration or programming error.\nFinally, this issue would not typically be under attacker control making active\nexploitation unlikely.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue.\n\nDue to the low severity of this issue we are not issuing new releases of\nOpenSSL at this time. The fix will be included in the next releases when they\nbecome available."},"relatedVulnerabilities":[]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.287375,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks."},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-0391","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2022-0391","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"risk":4.287375,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks."},"relatedVulnerabilities":[{"id":"CVE-2022-0391","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-0391","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-0391","date":"2026-10-08","epss":0.08325,"percentile":0.94816}],"urls":["https://bugs.python.org/issue43882","https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/","https://security.gentoo.org/glsa/202305-02","https://security.netapp.com/advisory/ntap-20220225-0009/","https://www.oracle.com/security-alerts/cpuapr2022.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-0391","description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14."}]},{"artifact":{"id":"7b479e2b1ed0e25e","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.34-5.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=libpng-1.6.34-5.el8.src.rpm","type":"rpm","version":"2:1.6.34-5.el8","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-7317","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libpng","version":"2:1.6.34-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-7317","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-7317","date":"2026-10-08","epss":0.09393,"percentile":0.95291}],"risk":3.898095,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-7317","description":"A vulnerability was found in libpng where a use-after-free issue exists in the png_image_free function within png.c. This vulnerability can be exploited by persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2019-7317","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:N/A:P","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-7317","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-7317","date":"2026-10-08","epss":0.09393,"percentile":0.95291}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00002.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00029.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00084.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00038.html","http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00044.html","http://packetstormsecurity.com/files/152561/Slackware-Security-Advisory-libpng-Updates.html","http://www.securityfocus.com/bid/108098","https://access.redhat.com/errata/RHSA-2019:1265","https://access.redhat.com/errata/RHSA-2019:1267","https://access.redhat.com/errata/RHSA-2019:1269","https://access.redhat.com/errata/RHSA-2019:1308","https://access.redhat.com/errata/RHSA-2019:1309","https://access.redhat.com/errata/RHSA-2019:1310","https://access.redhat.com/errata/RHSA-2019:2494","https://access.redhat.com/errata/RHSA-2019:2495","https://access.redhat.com/errata/RHSA-2019:2585","https://access.redhat.com/errata/RHSA-2019:2590","https://access.redhat.com/errata/RHSA-2019:2592","https://access.redhat.com/errata/RHSA-2019:2737","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12803","https://github.com/glennrp/libpng/issues/275","https://lists.debian.org/debian-lts-announce/2019/05/msg00032.html","https://lists.debian.org/debian-lts-announce/2019/05/msg00038.html","https://seclists.org/bugtraq/2019/Apr/30","https://seclists.org/bugtraq/2019/Apr/36","https://seclists.org/bugtraq/2019/May/56","https://seclists.org/bugtraq/2019/May/59","https://seclists.org/bugtraq/2019/May/67","https://security.gentoo.org/glsa/201908-02","https://security.netapp.com/advisory/ntap-20190719-0005/","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03977en_us","https://usn.ubuntu.com/3962-1/","https://usn.ubuntu.com/3991-1/","https://usn.ubuntu.com/3997-1/","https://usn.ubuntu.com/4080-1/","https://usn.ubuntu.com/4083-1/","https://www.debian.org/security/2019/dsa-4435","https://www.debian.org/security/2019/dsa-4448","https://www.debian.org/security/2019/dsa-4451","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://openjdk.org/groups/vulnerability/advisories/2019-07-16","https://www.mozilla.org/en-US/security/advisories/mfsa2019-13","https://www.mozilla.org/en-US/security/advisories/mfsa2019-14","https://www.mozilla.org/en-US/security/advisories/mfsa2019-15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-7317","description":"png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.10"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-3446","versionConstraint":">= 1.0.2, < 1.0.2zi||>= 1.1.1, < 1.1.1v||>= 3.0.0, < 3.0.10||>= 3.1.0, < 3.1.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-3446","fix":{"state":"fixed","versions":["1.0.2zi","1.1.1v","3.0.10","3.1.2"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.0.2zi"},{"date":"2025-09-04","kind":"first-observed","version":"1.1.1v"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.10"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-3446","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3446","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3446","date":"2026-10-08","epss":0.06531,"percentile":0.93621}],"risk":3.363465,"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1fa20cf2f506113c761777127a38bce5068740eb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=8780a896543a654e757db1b9396383f9d8095528","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9a0a4d3c1e7138915563c0df4fe6a3f9377b839c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc9867c1e03c22ebf56943be205202e576aabf23","https://www.openssl.org/news/secadv/20230719.txt","http://www.openwall.com/lists/oss-security/2023/07/19/4","http://www.openwall.com/lists/oss-security/2023/07/19/5","http://www.openwall.com/lists/oss-security/2023/07/19/6","http://www.openwall.com/lists/oss-security/2023/07/31/1","http://www.openwall.com/lists/oss-security/2024/05/16/1","https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230803-0011/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3446","description":"Issue summary: Checking excessively long DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_check(), DH_check_ex()\nor EVP_PKEY_param_check() to check a DH key or DH parameters may experience long\ndelays. Where the key or parameters that are being checked have been obtained\nfrom an untrusted source this may lead to a Denial of Service.\n\nThe function DH_check() performs various checks on DH parameters. One of those\nchecks confirms that the modulus ('p' parameter) is not too large. Trying to use\na very large modulus is slow and OpenSSL will not normally use a modulus which\nis over 10,000 bits in length.\n\nHowever the DH_check() function checks numerous aspects of the key or parameters\nthat have been supplied. Some of those checks use the supplied modulus value\neven if it has already been found to be too large.\n\nAn application that calls DH_check() and supplies a key or parameters obtained\nfrom an untrusted source could be vulernable to a Denial of Service attack.\n\nThe function DH_check() is itself called by a number of other OpenSSL functions.\nAn application calling any of those other functions may similarly be affected.\nThe other functions affected by this are DH_check_ex() and\nEVP_PKEY_param_check().\n\nAlso vulnerable are the OpenSSL dhparam and pkeyparam command line applications\nwhen using the '-check' option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-45447","versionConstraint":">= 1.0.2, < 1.0.2zq||>= 1.1.1, < 1.1.1zh||>= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"fixed","versions":["1.0.2zq","1.1.1zh","3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"1.0.2zq"},{"date":"2026-06-11","kind":"first-observed","version":"1.1.1zh"},{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.191595,"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:1.1.1k-16.el8_6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45447","versionConstraint":"< 1:1.1.1k-16.el8_6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-45447","fix":{"state":"fixed","versions":["1:1.1.1k-16.el8_6"],"available":[{"date":"2026-06-17","kind":"first-observed","version":"1:1.1.1k-16.el8_6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"risk":3.12156,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:26275","link":"https://access.redhat.com/errata/RHSA-2026:26275"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45447","description":"A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-45447","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45447","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2026-45447","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45447","date":"2026-10-08","epss":0.04002,"percentile":0.90276}],"urls":["https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c","https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8","https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54","https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c","https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e","https://openssl-library.org/news/secadv/20260609.txt","https://access.redhat.com/errata/RHSA-2026:25237","https://access.redhat.com/errata/RHSA-2026:25239","https://access.redhat.com/errata/RHSA-2026:26275","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:34102","https://access.redhat.com/errata/RHSA-2026:35869","https://access.redhat.com/errata/RHSA-2026:36215","https://access.redhat.com/errata/RHSA-2026:36217","https://access.redhat.com/errata/RHSA-2026:39009","https://access.redhat.com/errata/RHSA-2026:39012","https://access.redhat.com/errata/RHSA-2026:39981","https://access.redhat.com/errata/RHSA-2026:44438","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:58563","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:66524","https://access.redhat.com/security/cve/CVE-2026-45447","https://bugzilla.redhat.com/show_bug.cgi?id=2481898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45447","description":"Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-9143","versionConstraint":">= 1.0.2, < 1.0.2zl||>= 1.1.1, < 1.1.1zb||>= 3.0.0, < 3.0.16||>= 3.1.0, < 3.1.8||>= 3.2.0, < 3.2.4||>= 3.3.0, < 3.3.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-9143","fix":{"state":"fixed","versions":["1.0.2zl","1.1.1zb","3.0.16","3.1.8","3.2.4","3.3.3"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.0.2zl"},{"date":"2025-09-04","kind":"first-observed","version":"1.1.1zb"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.16"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.8"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.4"},{"date":"2025-09-04","kind":"first-observed","version":"3.3.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9143","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-9143","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-9143","date":"2026-10-08","epss":0.05842,"percentile":0.92986}],"risk":2.7165299999999997,"urls":["https://github.com/openssl/openssl/commit/72ae83ad214d2eef262461365a1975707f862712","https://github.com/openssl/openssl/commit/bc7e04d7c8d509fb78fc0e285aa948fb0da04700","https://github.com/openssl/openssl/commit/c0d3e4d32d2805f49bec30547f225bc4d092e1f4","https://github.com/openssl/openssl/commit/fdf6723362ca51bd883295efe206cb5b1cfa5154","https://github.openssl.org/openssl/extended-releases/commit/8efc0cbaa8ebba8e116f7b81a876a4123594d86a","https://github.openssl.org/openssl/extended-releases/commit/9d576994cec2b7aa37a91740ea7e680810957e41","https://openssl-library.org/news/secadv/20241016.txt","http://www.openwall.com/lists/oss-security/2024/10/16/1","http://www.openwall.com/lists/oss-security/2024/10/23/1","http://www.openwall.com/lists/oss-security/2024/10/24/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20241101-0001/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9143","description":"Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted\nexplicit values for the field polynomial can lead to out-of-bounds memory reads\nor writes.\n\nImpact summary: Out of bound memory writes can lead to an application crash or\neven a possibility of a remote code execution, however, in all the protocols\ninvolving Elliptic Curve Cryptography that we're aware of, either only \"named\ncurves\" are supported, or, if explicit curve parameters are supported, they\nspecify an X9.62 encoding of binary (GF(2^m)) curves that can't represent\nproblematic input values. Thus the likelihood of existence of a vulnerable\napplication is low.\n\nIn particular, the X9.62 encoding is used for ECC keys in X.509 certificates,\nso problematic inputs cannot occur in the context of processing X.509\ncertificates.  Any problematic use-cases would have to be using an \"exotic\"\ncurve encoding.\n\nThe affected APIs include: EC_GROUP_new_curve_GF2m(), EC_GROUP_new_from_params(),\nand various supporting BN_GF2m_*() functions.\n\nApplications working with \"exotic\" explicit binary (GF(2^m)) curve parameters,\nthat make it possible to represent invalid field polynomials with a zero\nconstant term, via the above or similar APIs, may terminate abruptly as a\nresult of reading or writing outside of array bounds.  Remote code execution\ncannot easily be ruled out.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.12"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-5363","versionConstraint":">= 3.0.0, < 3.0.12||>= 3.1.0, < 3.1.4 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-5363","fix":{"state":"fixed","versions":["3.0.12","3.1.4"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"3.0.12"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.4"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5363","cwe":"CWE-684","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2023-5363","date":"2026-10-08","epss":0.03332,"percentile":0.88291}],"risk":2.499,"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0df40630850fb2740e6be6890bb905d3fc623b2d","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=5f69f5c65e483928c4b28ed16af6e5742929f1ee","https://www.openssl.org/news/secadv/20231024.txt","http://www.openwall.com/lists/oss-security/2023/10/24/1","https://security.netapp.com/advisory/ntap-20231027-0010/","https://security.netapp.com/advisory/ntap-20240201-0003/","https://security.netapp.com/advisory/ntap-20240201-0004/","https://security.netapp.com/advisory/ntap-20241108-0002/","https://www.debian.org/security/2023/dsa-5532","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5363","description":"Issue summary: A bug has been identified in the processing of key and\ninitialisation vector (IV) lengths.  This can lead to potential truncation\nor overruns during the initialisation of some symmetric ciphers.\n\nImpact summary: A truncation in the IV can result in non-uniqueness,\nwhich could result in loss of confidentiality for some cipher modes.\n\nWhen calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or\nEVP_CipherInit_ex2() the provided OSSL_PARAM array is processed after\nthe key and IV have been established.  Any alterations to the key length,\nvia the \"keylen\" parameter or the IV length, via the \"ivlen\" parameter,\nwithin the OSSL_PARAM array will not take effect as intended, potentially\ncausing truncation or overreading of these values.  The following ciphers\nand cipher modes are impacted: RC2, RC4, RC5, CCM, GCM and OCB.\n\nFor the CCM, GCM and OCB cipher modes, truncation of the IV can result in\nloss of confidentiality.  For example, when following NIST's SP 800-38D\nsection 8.2.1 guidance for constructing a deterministic IV for AES in\nGCM mode, truncation of the counter portion could lead to IV reuse.\n\nBoth truncations and overruns of the key and overruns of the IV will\nproduce incorrect results and could, in some cases, trigger a memory\nexception.  However, these issues are not currently assessed as security\ncritical.\n\nChanging the key and/or IV lengths is not considered to be a common operation\nand the vulnerable API was recently introduced. Furthermore it is likely that\napplication developers will have spotted this problem during testing since\ndecryption would fail unless both peers in the communication were similarly\nvulnerable. For these reasons we expect the probability of an application being\nvulnerable to this to be quite low. However if an application is vulnerable then\nthis issue is considered very serious. For these reasons we have assessed this\nissue as Moderate severity overall.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this because\nthe issue lies outside of the FIPS provider boundary.\n\nOpenSSL 3.1 and 3.0 are vulnerable to this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"2fd8ac9813678144","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.26.0-19.el8_9?arch=x86_64&distro=rhel-8.10&upstream=sqlite-3.26.0-19.el8_9.src.rpm","type":"rpm","version":"3.26.0-19.el8_9","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.26.0-19.el8_9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9937","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"sqlite","version":"3.26.0-19.el8_9"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-9937","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9937","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9937","date":"2026-10-08","epss":0.06011,"percentile":0.93154}],"risk":2.494565,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-9937","description":"A vulnerability was found in SQLite due to a NULL pointer dereference in the fts5ChunkIterate function within sqlite3.c, where an attacker could exploit this flaw by creating a specially crafted table, causing the application to crash and resulting in a denial of service condition."},"relatedVulnerabilities":[{"id":"CVE-2019-9937","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9937","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9937","date":"2026-10-08","epss":0.06011,"percentile":0.93154}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html","http://www.securityfocus.com/bid/107562","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/","https://security.gentoo.org/glsa/201908-09","https://security.netapp.com/advisory/ntap-20190416-0005/","https://sqlite.org/src/info/45c73deb440496e8","https://usn.ubuntu.com/4019-1/","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114383.html","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114393.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9937","description":"In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c."}]},{"artifact":{"id":"1435e8d59fac6b89","cpes":["cpe:2.3:a:redhat:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.30-9.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=tar-1.30-9.el8.src.rpm","type":"rpm","version":"2:1.30-9.el8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"tar","version":"2:1.30-9.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"risk":2.3951999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2005-2541","description":"A flaw was found in tar utility that can allow the root user to extract files with preserved setuid and setgid permissions without any warning. This behavior can lead to the creation of malicious setuid executables owned by root from a crafted tar file, posing significant security risks."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-08","epss":0.03992,"percentile":0.9025}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-5678","versionConstraint":">= 1.0.2, < 1.0.2zj||>= 1.1.1, < 1.1.1x||>= 3.0.0, < 3.0.13||>= 3.1.0, < 3.1.5 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-5678","fix":{"state":"fixed","versions":["1.0.2zj","1.1.1x","3.0.13","3.1.5"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.0.2zj"},{"date":"2025-09-04","kind":"first-observed","version":"1.1.1x"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.13"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.5"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-5678","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-5678","cwe":"CWE-754","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-5678","date":"2026-10-08","epss":0.04459,"percentile":0.9119}],"risk":2.296385,"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=34efaef6c103d636ab507a0cc34dca4d3aecc055","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=710fee740904b6290fef0dd5536fbcedbc38ff0c","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=db925ae2e65d0d925adef429afc37f75bd1c2017","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=ddeb4b6c6d527e54ce9a99cba785c0f7776e54b6","https://www.openssl.org/news/secadv/20231106.txt","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20231130-0010/","https://cert-portal.siemens.com/productcert/html/ssa-093430.html","https://cert-portal.siemens.com/productcert/html/ssa-128433.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-341067.html","https://cert-portal.siemens.com/productcert/html/ssa-398330.html","https://cert-portal.siemens.com/productcert/html/ssa-556635.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-794697.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-5678","description":"Issue summary: Generating excessively long X9.42 DH keys or checking\nexcessively long X9.42 DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_generate_key() to\ngenerate an X9.42 DH key may experience long delays.  Likewise, applications\nthat use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check()\nto check an X9.42 DH key or X9.42 DH parameters may experience long delays.\nWhere the key or parameters that are being checked have been obtained from\nan untrusted source this may lead to a Denial of Service.\n\nWhile DH_check() performs all the necessary checks (as of CVE-2023-3817),\nDH_check_pub_key() doesn't make any of these checks, and is therefore\nvulnerable for excessively large P and Q parameters.\n\nLikewise, while DH_generate_key() performs a check for an excessively large\nP, it doesn't check for an excessively large Q.\n\nAn application that calls DH_generate_key() or DH_check_pub_key() and\nsupplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\n\nDH_generate_key() and DH_check_pub_key() are also called by a number of\nother OpenSSL functions.  An application calling any of those other\nfunctions may similarly be affected.  The other functions affected by this\nare DH_check_pub_key_ex(), EVP_PKEY_public_check(), and EVP_PKEY_generate().\n\nAlso vulnerable are the OpenSSL pkey command line application when using the\n\"-pubcheck\" option, as well as the OpenSSL genpkey command line application.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-1.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-23990","versionConstraint":"< 0:2.5.0-1.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2022-23990","fix":{"state":"fixed","versions":["0:2.5.0-1.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.5.0-1.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23990","date":"2026-10-08","epss":0.03992,"percentile":0.90252}],"risk":2.2953999999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:21776","link":"https://access.redhat.com/errata/RHSA-2025:21776"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-23990","description":"A flaw was found in expat. The vulnerability occurs due to large content in element type declarations when there is an element declaration handler present which leads to an integer overflow. This flaw allows an attacker to inject an unsigned integer, leading to a crash or a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-23990","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23990","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23990","date":"2026-10-08","epss":0.03992,"percentile":0.90252}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-484086.pdf","https://github.com/libexpat/libexpat/pull/551","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/34NXVL2RZC2YZRV74ZQ3RNFB7WCEUP7D/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R7FF2UH7MPXKTADYSJUAHI2Y5UHBSHUH/","https://security.gentoo.org/glsa/202209-24","https://www.debian.org/security/2022/dsa-5073","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.tenable.com/security/tns-2022-05"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23990","description":"Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function."}]},{"artifact":{"id":"690a68ab4ef32559","cpes":["cpe:2.3:a:python:urllib3:2.4.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.4.0","type":"python","version":"2.4.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.6.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-38jv-5279-wg99","versionConstraint":">=1.22,<2.6.3 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.4.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-38jv-5279-wg99","fix":{"state":"fixed","versions":["2.6.3"],"available":[{"date":"2026-01-08","kind":"first-observed","version":"2.6.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-21441","date":"2026-10-08","epss":0.02922,"percentile":0.86636}],"risk":2.29377,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99","https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b","https://nvd.nist.gov/vuln/detail/CVE-2026-21441","https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-38jv-5279-wg99","description":"Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)"},"relatedVulnerabilities":[{"id":"CVE-2026-21441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-21441","date":"2026-10-08","epss":0.02922,"percentile":0.86636}],"urls":["https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b","https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99","https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html","https://access.redhat.com/errata/RHSA-2026:0981","https://access.redhat.com/errata/RHSA-2026:0990","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:1038","https://access.redhat.com/errata/RHSA-2026:1041","https://access.redhat.com/errata/RHSA-2026:1042","https://access.redhat.com/errata/RHSA-2026:1086","https://access.redhat.com/errata/RHSA-2026:1087","https://access.redhat.com/errata/RHSA-2026:1088","https://access.redhat.com/errata/RHSA-2026:1089","https://access.redhat.com/errata/RHSA-2026:1166","https://access.redhat.com/errata/RHSA-2026:1168","https://access.redhat.com/errata/RHSA-2026:1176","https://access.redhat.com/errata/RHSA-2026:1224","https://access.redhat.com/errata/RHSA-2026:1226","https://access.redhat.com/errata/RHSA-2026:1239","https://access.redhat.com/errata/RHSA-2026:1240","https://access.redhat.com/errata/RHSA-2026:1241","https://access.redhat.com/errata/RHSA-2026:1254","https://access.redhat.com/errata/RHSA-2026:1485","https://access.redhat.com/errata/RHSA-2026:14877","https://access.redhat.com/errata/RHSA-2026:1504","https://access.redhat.com/errata/RHSA-2026:1546","https://access.redhat.com/errata/RHSA-2026:1596","https://access.redhat.com/errata/RHSA-2026:1599","https://access.redhat.com/errata/RHSA-2026:1609","https://access.redhat.com/errata/RHSA-2026:1618","https://access.redhat.com/errata/RHSA-2026:1619","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:1674","https://access.redhat.com/errata/RHSA-2026:1676","https://access.redhat.com/errata/RHSA-2026:1693","https://access.redhat.com/errata/RHSA-2026:1704","https://access.redhat.com/errata/RHSA-2026:1706","https://access.redhat.com/errata/RHSA-2026:1712","https://access.redhat.com/errata/RHSA-2026:1717","https://access.redhat.com/errata/RHSA-2026:1726","https://access.redhat.com/errata/RHSA-2026:1729","https://access.redhat.com/errata/RHSA-2026:1730","https://access.redhat.com/errata/RHSA-2026:1734","https://access.redhat.com/errata/RHSA-2026:1735","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:17456","https://access.redhat.com/errata/RHSA-2026:17457","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17461","https://access.redhat.com/errata/RHSA-2026:17462","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:1791","https://access.redhat.com/errata/RHSA-2026:1792","https://access.redhat.com/errata/RHSA-2026:1793","https://access.redhat.com/errata/RHSA-2026:1794","https://access.redhat.com/errata/RHSA-2026:1803","https://access.redhat.com/errata/RHSA-2026:1805","https://access.redhat.com/errata/RHSA-2026:1942","https://access.redhat.com/errata/RHSA-2026:1957","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:2106","https://access.redhat.com/errata/RHSA-2026:2126","https://access.redhat.com/errata/RHSA-2026:2137","https://access.redhat.com/errata/RHSA-2026:2139","https://access.redhat.com/errata/RHSA-2026:2144","https://access.redhat.com/errata/RHSA-2026:2256","https://access.redhat.com/errata/RHSA-2026:2456","https://access.redhat.com/errata/RHSA-2026:2500","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2695","https://access.redhat.com/errata/RHSA-2026:2717","https://access.redhat.com/errata/RHSA-2026:2718","https://access.redhat.com/errata/RHSA-2026:2723","https://access.redhat.com/errata/RHSA-2026:2728","https://access.redhat.com/errata/RHSA-2026:2760","https://access.redhat.com/errata/RHSA-2026:2762","https://access.redhat.com/errata/RHSA-2026:2764","https://access.redhat.com/errata/RHSA-2026:2765","https://access.redhat.com/errata/RHSA-2026:28043","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:2900","https://access.redhat.com/errata/RHSA-2026:2911","https://access.redhat.com/errata/RHSA-2026:2919","https://access.redhat.com/errata/RHSA-2026:2924","https://access.redhat.com/errata/RHSA-2026:2925","https://access.redhat.com/errata/RHSA-2026:2926","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:33154","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:3444","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:4185","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:4215","https://access.redhat.com/errata/RHSA-2026:4271","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:44696","https://access.redhat.com/errata/RHSA-2026:51357","https://access.redhat.com/errata/RHSA-2026:5459","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:6287","https://access.redhat.com/errata/RHSA-2026:6292","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8500","https://access.redhat.com/errata/RHSA-2026:8501","https://access.redhat.com/security/cve/CVE-2026-21441","https://bugzilla.redhat.com/show_bug.cgi?id=2427726","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441","description":"urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.14"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-4741","versionConstraint":">= 1.1.1, < 1.1.1y||>= 3.0.0, < 3.0.14||>= 3.1.0, < 3.1.6||>= 3.2.0, < 3.2.2||>= 3.3.0, < 3.3.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-4741","fix":{"state":"fixed","versions":["1.1.1y","3.0.14","3.1.6","3.2.2","3.3.1"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.1.1y"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.14"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.6"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.2"},{"date":"2025-09-04","kind":"first-observed","version":"3.3.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-4741","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-4741","date":"2026-10-08","epss":0.02925,"percentile":0.86654}],"risk":2.19375,"urls":["https://github.com/openssl/openssl/commit/704f725b96aa373ee45ecfb23f6abfe8be8d9177","https://github.com/openssl/openssl/commit/b3f0eb0a295f58f16ba43ba99dad70d4ee5c437d","https://github.com/openssl/openssl/commit/c88c3de51020c37e8706bf7a682a162593053aac","https://github.com/openssl/openssl/commit/e5093133c35ca82874ad83697af76f4b0f7e3bd8","https://github.openssl.org/openssl/extended-releases/commit/f7a045f3143fc6da2ee66bf52d8df04829590dd4","https://www.openssl.org/news/secadv/20240528.txt","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240621-0004/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-4741","description":"Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause\nmemory to be accessed that was previously freed in some situations\n\nImpact summary: A use after free can have a range of potential consequences such\nas the corruption of valid data, crashes or execution of arbitrary code.\nHowever, only applications that directly call the SSL_free_buffers function are\naffected by this issue. Applications that do not call this function are not\nvulnerable. Our investigations indicate that this function is rarely used by\napplications.\n\nThe SSL_free_buffers function is used to free the internal OpenSSL buffer used\nwhen processing an incoming record from the network. The call is only expected\nto succeed if the buffer is not currently in use. However, two scenarios have\nbeen identified where the buffer is freed even when still in use.\n\nThe first scenario occurs where a record header has been received from the\nnetwork and processed by OpenSSL, but the full record body has not yet arrived.\nIn this case calling SSL_free_buffers will succeed even though a record has only\nbeen partially processed and the buffer is still in use.\n\nThe second scenario occurs where a full record containing application data has\nbeen received and processed by OpenSSL but the application has only read part of\nthis data. Again a call to SSL_free_buffers will succeed even though the buffer\nis still in use.\n\nWhile these scenarios could occur accidentally during normal operation a\nmalicious attacker could attempt to engineer a stituation where this occurs.\nWe are not aware of this issue being actively exploited.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-9674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9674","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9674","date":"2026-10-08","epss":0.0549,"percentile":0.92572}],"risk":1.9763999999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-9674","description":"A ZIP bomb attack was found in the Python zipfile module. A remote attacker could abuse this flaw by providing a specially crafted ZIP file that, when decompressed by zipfile, would exhaust system resources resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2019-9674","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9674","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9674","date":"2026-10-08","epss":0.0549,"percentile":0.92572}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html","https://bugs.python.org/issue36260","https://bugs.python.org/issue36462","https://github.com/python/cpython/blob/master/Lib/zipfile.py","https://python-security.readthedocs.io/security.html#archives-and-zip-bomb","https://security.netapp.com/advisory/ntap-20200221-0003/","https://usn.ubuntu.com/4428-1/","https://www.python.org/news/security/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9674","description":"Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9674","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-9674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9674","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9674","date":"2026-10-08","epss":0.0549,"percentile":0.92572}],"risk":1.9763999999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-9674","description":"A ZIP bomb attack was found in the Python zipfile module. A remote attacker could abuse this flaw by providing a specially crafted ZIP file that, when decompressed by zipfile, would exhaust system resources resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2019-9674","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9674","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9674","date":"2026-10-08","epss":0.0549,"percentile":0.92572}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html","https://bugs.python.org/issue36260","https://bugs.python.org/issue36462","https://github.com/python/cpython/blob/master/Lib/zipfile.py","https://python-security.readthedocs.io/security.html#archives-and-zip-bomb","https://security.netapp.com/advisory/ntap-20200221-0003/","https://usn.ubuntu.com/4428-1/","https://www.python.org/news/security/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9674","description":"Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.20"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-28388","versionConstraint":">= 1.0.2, < 1.0.2zp||>= 1.1.1, < 1.1.1zg||>= 3.0.0, < 3.0.20||>= 3.3.0, < 3.3.7||>= 3.4.0, < 3.4.5||>= 3.5.0, < 3.5.6||>= 3.6.0, < 3.6.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"fixed","versions":["1.0.2zp","1.1.1zg","3.0.20","3.3.7","3.4.5","3.5.6","3.6.2"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"1.0.2zp"},{"date":"2026-04-09","kind":"first-observed","version":"1.1.1zg"},{"date":"2026-04-09","kind":"first-observed","version":"3.0.20"},{"date":"2026-04-09","kind":"first-observed","version":"3.3.7"},{"date":"2026-04-09","kind":"first-observed","version":"3.4.5"},{"date":"2026-04-09","kind":"first-observed","version":"3.5.6"},{"date":"2026-04-09","kind":"first-observed","version":"3.6.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":1.87575,"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.20"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-28389","versionConstraint":">= 1.0.2, < 1.0.2zp||>= 1.1.1, < 1.1.1zg||>= 3.0.0, < 3.0.20||>= 3.3.0, < 3.3.7||>= 3.4.0, < 3.4.5||>= 3.5.0, < 3.5.6||>= 3.6.0, < 3.6.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"fixed","versions":["1.0.2zp","1.1.1zg","3.0.20","3.3.7","3.4.5","3.5.6","3.6.2"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"1.0.2zp"},{"date":"2026-04-09","kind":"first-observed","version":"1.1.1zg"},{"date":"2026-04-09","kind":"first-observed","version":"3.0.20"},{"date":"2026-04-09","kind":"first-observed","version":"3.3.7"},{"date":"2026-04-09","kind":"first-observed","version":"3.4.5"},{"date":"2026-04-09","kind":"first-observed","version":"3.5.6"},{"date":"2026-04-09","kind":"first-observed","version":"3.6.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":1.8262500000000002,"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"2fd8ac9813678144","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.26.0-19.el8_9?arch=x86_64&distro=rhel-8.10&upstream=sqlite-3.26.0-19.el8_9.src.rpm","type":"rpm","version":"3.26.0-19.el8_9","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.26.0-19.el8_9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-19244","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"sqlite","version":"3.26.0-19.el8_9"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-19244","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19244","date":"2026-10-08","epss":0.03333,"percentile":0.88292}],"risk":1.749825,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-19244","description":"A flaw was found in the way SQLite handled certain types of SQL queries using DISTINCT, OVER and ORDER BY clauses. A remote attacker could exploit this flaw by providing a malicious SQL query that, when processed by an application linked to SQLite, would crash the application causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2019-19244","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-19244","date":"2026-10-08","epss":0.03333,"percentile":0.88292}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","https://github.com/sqlite/sqlite/commit/e59c562b3f6894f84c715772c4b116d7b5c01348","https://usn.ubuntu.com/4205-1/","https://www.oracle.com/security-alerts/cpuapr2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-19244","description":"sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-0727","versionConstraint":">= 1.0.2, < 1.0.2zj||>= 1.1.1, < 1.1.1x||>= 3.0.0, < 3.0.13||>= 3.1.0, < 3.1.5||= 3.2.0 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-0727","fix":{"state":"fixed","versions":["1.0.2zj","1.1.1x","3.0.13","3.1.5"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.0.2zj"},{"date":"2025-09-04","kind":"first-observed","version":"1.1.1x"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.13"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.5"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0727","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-0727","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0727","date":"2026-10-08","epss":0.03187,"percentile":0.877}],"risk":1.6731750000000003,"urls":["https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2","https://github.com/openssl/openssl/commit/775acfdbd0c6af9ac855f34969cdab0c0c90844a","https://github.com/openssl/openssl/commit/d135eeab8a5dbf72b3da5240bab9ddb7678dbd2c","https://github.openssl.org/openssl/extended-releases/commit/03b3941d60c4bce58fab69a0c22377ab439bc0e8","https://github.openssl.org/openssl/extended-releases/commit/aebaa5883e31122b404e450732dc833dc9dee539","https://www.openssl.org/news/secadv/20240125.txt","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240208-0006/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0727","description":"Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL\nto crash leading to a potential Denial of Service attack\n\nImpact summary: Applications loading files in the PKCS12 format from untrusted\nsources might terminate abruptly.\n\nA file in PKCS12 format can contain certificates and keys and may come from an\nuntrusted source. The PKCS12 specification allows certain fields to be NULL, but\nOpenSSL does not correctly check for this case. This can lead to a NULL pointer\ndereference that results in OpenSSL crashing. If an application processes PKCS12\nfiles from an untrusted source using the OpenSSL APIs then that application will\nbe vulnerable to this issue.\n\nOpenSSL APIs that are vulnerable to this are: PKCS12_parse(),\nPKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes()\nand PKCS12_newpass().\n\nWe have also fixed a similar issue in SMIME_write_PKCS7(). However since this\nfunction is related to writing data we do not consider it security significant.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-0464","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-0464","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0464","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0464","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0464","date":"2026-10-08","epss":0.03658,"percentile":0.89322}],"risk":1.6278100000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-0464","description":"A security vulnerability has been identified in all supported OpenSSL versions related to verifying X.509 certificate chains that include policy constraints. This flaw allows attackers to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial of service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the -policy' argument to the command line utilities or calling the X509_VERIFY_PARAM_set1_policies()' function."},"relatedVulnerabilities":[{"id":"CVE-2023-0464","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0464","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0464","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0464","date":"2026-10-08","epss":0.03658,"percentile":0.89322}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2017771e2db3e2b96f89bbe8766c3209f6a99545","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=2dcd4f1e3115f38cefa43e3efbe9b801c27e642e","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=879f7080d7e141f415c79eaa3a8ac4a3dad0348b","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=959c59c7a0164117e7f8366466a32bb1f8d77ff1","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20240621-0006/","https://www.couchbase.com/alerts/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230322.txt","https://security.netapp.com/advisory/ntap-20230406-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0464","description":"A security vulnerability has been identified in all supported versions\n\nof OpenSSL related to the verification of X.509 certificate chains\nthat include policy constraints.  Attackers may be able to exploit this\nvulnerability by creating a malicious certificate chain that triggers\nexponential use of computational resources, leading to a denial-of-service\n(DoS) attack on affected systems.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.10"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-3817","versionConstraint":">= 3.0.0, < 3.0.10||>= 3.1.0, < 3.1.2||= 1.0.2||= 1.0.2-beta1||= 1.0.2-beta2||= 1.0.2-beta3||= 1.0.2a||= 1.0.2b||= 1.0.2c||= 1.0.2d||= 1.0.2e||= 1.0.2f||= 1.0.2g||= 1.0.2h||= 1.0.2i||= 1.0.2j||= 1.0.2k||= 1.0.2l||= 1.0.2m||= 1.0.2n||= 1.0.2o||= 1.0.2p||= 1.0.2q||= 1.0.2r||= 1.0.2s||= 1.0.2t||= 1.0.2u||= 1.0.2v||= 1.0.2w||= 1.0.2x||= 1.0.2y||= 1.0.2za||= 1.0.2zb||= 1.0.2zc||= 1.0.2zd||= 1.0.2ze||= 1.0.2zf||= 1.0.2zg||= 1.0.2zh||= 1.1.1||= 1.1.1-pre1||= 1.1.1-pre2||= 1.1.1-pre3||= 1.1.1-pre4||= 1.1.1-pre5||= 1.1.1-pre6||= 1.1.1-pre7||= 1.1.1-pre8||= 1.1.1-pre9||= 1.1.1a||= 1.1.1b||= 1.1.1c||= 1.1.1d||= 1.1.1e||= 1.1.1f||= 1.1.1g||= 1.1.1h||= 1.1.1i||= 1.1.1j||= 1.1.1k||= 1.1.1l||= 1.1.1m||= 1.1.1n||= 1.1.1o||= 1.1.1p||= 1.1.1q||= 1.1.1r||= 1.1.1s||= 1.1.1t||= 1.1.1u (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-3817","fix":{"state":"fixed","versions":["3.0.10","3.1.2"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"3.0.10"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-3817","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-3817","cwe":"CWE-834","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-3817","date":"2026-10-08","epss":0.03047,"percentile":0.87153}],"risk":1.569205,"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=6a1eb62c29db6cb5eec707f9338aee00f44e26f5","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=869ad69aadd985c7b8ca6f4e5dd0eb274c9f3644","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=9002fd07327a91f35ba6c1307e71fa6fd4409b7f","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=91ddeba0f2269b017dc06c46c993a788974b1aa5","https://www.openssl.org/news/secadv/20230731.txt","http://seclists.org/fulldisclosure/2023/Jul/43","http://www.openwall.com/lists/oss-security/2023/07/31/1","http://www.openwall.com/lists/oss-security/2023/09/22/11","http://www.openwall.com/lists/oss-security/2023/09/22/9","http://www.openwall.com/lists/oss-security/2023/11/06/2","https://lists.debian.org/debian-lts-announce/2023/08/msg00019.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230818-0014/","https://security.netapp.com/advisory/ntap-20231027-0008/","https://security.netapp.com/advisory/ntap-20240621-0006/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-3817","description":"Issue summary: Checking excessively long DH keys or parameters may be very slow.\n\nImpact summary: Applications that use the functions DH_check(), DH_check_ex()\nor EVP_PKEY_param_check() to check a DH key or DH parameters may experience long\ndelays. Where the key or parameters that are being checked have been obtained\nfrom an untrusted source this may lead to a Denial of Service.\n\nThe function DH_check() performs various checks on DH parameters. After fixing\nCVE-2023-3446 it was discovered that a large q parameter value can also trigger\nan overly long computation during some of these checks. A correct q value,\nif present, cannot be larger than the modulus p parameter, thus it is\nunnecessary to perform these checks if q is larger than p.\n\nAn application that calls DH_check() and supplies a key or parameters obtained\nfrom an untrusted source could be vulnerable to a Denial of Service attack.\n\nThe function DH_check() is itself called by a number of other OpenSSL functions.\nAn application calling any of those other functions may similarly be affected.\nThe other functions affected by this are DH_check_ex() and\nEVP_PKEY_param_check().\n\nAlso vulnerable are the OpenSSL dhparam and pkeyparam command line applications\nwhen using the \"-check\" option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"2fd8ac9813678144","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.26.0-19.el8_9?arch=x86_64&distro=rhel-8.10&upstream=sqlite-3.26.0-19.el8_9.src.rpm","type":"rpm","version":"3.26.0-19.el8_9","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.26.0-19.el8_9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9936","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"sqlite","version":"3.26.0-19.el8_9"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-9936","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9936","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9936","date":"2026-10-08","epss":0.04843,"percentile":0.91782}],"risk":1.525545,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-9936","description":"A vulnerability was found in SQLite, where a heap-based buffer over-read occurs in the fts5HashEntrySort function within sqlite3.c, an attacker could exploit this vulnerability by running specially crafted queries, lead to an information leak."},"relatedVulnerabilities":[{"id":"CVE-2019-9936","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9936","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9936","date":"2026-10-08","epss":0.04843,"percentile":0.91782}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00026.html","http://www.securityfocus.com/bid/107562","https://lists.debian.org/debian-lts-announce/2020/08/msg00037.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EXD2GYJVTDGEQPUNMMMC5TB7MQXOBBMO/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N66U5PY5UJU4XBFZJH7QNKIDNAVIB4OP/","https://security.gentoo.org/glsa/201908-09","https://security.netapp.com/advisory/ntap-20190416-0005/","https://sqlite.org/src/info/b3fa58dd7403dbd4","https://usn.ubuntu.com/4019-1/","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114382.html","https://www.mail-archive.com/sqlite-users%40mailinglists.sqlite.org/msg114394.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9936","description":"In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c."}]},{"artifact":{"id":"ef94ba4010621fba","cpes":["cpe:2.3:a:apache:commons-beanutils:1.9.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_beanutils:1.9.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:1.9.4:*:*:*:*:*:*:*"],"name":"commons-beanutils","purl":"pkg:maven/commons-beanutils/commons-beanutils@1.9.4","type":"java-archive","version":"1.9.4","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"commons-beanutils","virtualPath":"/usr/share/java/cp-base-new/commons-beanutils-1.9.4.jar","manifestName":"","pomArtifactID":"commons-beanutils","archiveDigests":[{"value":"d52b9abcd97f38c81342bb7e7ae1eee9b73cba51","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/commons-beanutils-1.9.4.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/commons-beanutils-1.9.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wxr5-93ph-8wr9","versionConstraint":">=1.0,<=1.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"commons-beanutils:commons-beanutils","version":"1.9.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wxr5-93ph-8wr9","fix":{"state":"fixed","versions":["1.11.0"],"available":[{"date":"2025-05-29","kind":"first-observed","version":"1.11.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48734","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-48734","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-48734","date":"2026-10-08","epss":0.01825,"percentile":0.78153}],"risk":1.487375,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48734","https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9","https://github.com/apache/commons-beanutils/commit/bd20740da25b69552ddef8523beec0837297eaf9","http://www.openwall.com/lists/oss-security/2025/05/28/6","https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wxr5-93ph-8wr9","description":"Apache Commons Improper Access Control vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2025-48734","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48734","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-48734","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-48734","date":"2026-10-08","epss":0.01825,"percentile":0.78153}],"urls":["https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9","http://www.openwall.com/lists/oss-security/2025/05/28/6","https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48734","description":"Improper Access Control vulnerability in Apache Commons.\n\n\n\nA special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.\n\n\n\n\n\nReleases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().\nStarting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user's guide and the unit tests.\n\nThis issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils\n\n 1.x are recommended to upgrade to version 1.11.0, which fixes the issue.\n\n\nUsers of the artifact org.apache.commons:commons-beanutils2\n\n 2.x are recommended to upgrade to version 2.0.0-M2, which fixes the issue."}]},{"artifact":{"id":"b8b7a6b2073f6e87","cpes":["cpe:2.3:a:apache:commons-beanutils:1.9.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_beanutils:1.9.4:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:1.9.4:*:*:*:*:*:*:*"],"name":"commons-beanutils","purl":"pkg:maven/commons-beanutils/commons-beanutils@1.9.4","type":"java-archive","version":"1.9.4","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"commons-beanutils","virtualPath":"/usr/share/java/kafka/commons-beanutils-1.9.4.jar","manifestName":"","pomArtifactID":"commons-beanutils","archiveDigests":[{"value":"d52b9abcd97f38c81342bb7e7ae1eee9b73cba51","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/commons-beanutils-1.9.4.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/commons-beanutils-1.9.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.11.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wxr5-93ph-8wr9","versionConstraint":">=1.0,<=1.10.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"commons-beanutils:commons-beanutils","version":"1.9.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wxr5-93ph-8wr9","fix":{"state":"fixed","versions":["1.11.0"],"available":[{"date":"2025-05-29","kind":"first-observed","version":"1.11.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48734","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-48734","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-48734","date":"2026-10-08","epss":0.01825,"percentile":0.78153}],"risk":1.487375,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48734","https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9","https://github.com/apache/commons-beanutils/commit/bd20740da25b69552ddef8523beec0837297eaf9","http://www.openwall.com/lists/oss-security/2025/05/28/6","https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wxr5-93ph-8wr9","description":"Apache Commons Improper Access Control vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2025-48734","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48734","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2025-48734","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-48734","date":"2026-10-08","epss":0.01825,"percentile":0.78153}],"urls":["https://lists.apache.org/thread/s0hb3jkfj5f3ryx6c57zqtfohb0of1g9","http://www.openwall.com/lists/oss-security/2025/05/28/6","https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48734","description":"Improper Access Control vulnerability in Apache Commons.\n\n\n\nA special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.\n\n\n\n\n\nReleases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty().\nStarting in versions 1.11.0 and 2.0.0-M2 a special BeanIntrospector suppresses the “declaredClass” property. Note that this new BeanIntrospector is enabled by default, but you can disable it to regain the old behavior; see section 2.5 of the user's guide and the unit tests.\n\nThis issue affects Apache Commons BeanUtils 1.x before 1.11.0, and 2.x before 2.0.0-M2.Users of the artifact commons-beanutils:commons-beanutils\n\n 1.x are recommended to upgrade to version 1.11.0, which fixes the issue.\n\n\nUsers of the artifact org.apache.commons:commons-beanutils2\n\n 2.x are recommended to upgrade to version 2.0.0-M2, which fixes the issue."}]},{"artifact":{"id":"15ab448eaed3b129","cpes":["cpe:2.3:a:libarchive:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.3.3-5.el8?arch=x86_64&distro=rhel-8.10&upstream=libarchive-3.3.3-5.el8.src.rpm","type":"rpm","version":"3.3.3-5.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1000880","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libarchive","version":"0:3.3.3-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-1000880","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000880","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000880","date":"2026-10-08","epss":0.04056,"percentile":0.90389}],"risk":1.48044,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-1000880","description":"A vulnerability was found in libarchive, where improper input validation in the _warc_read function in libarchive/archive_read_support_format_warc.c can lead to a denial of service, a remote attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash."},"relatedVulnerabilities":[{"id":"CVE-2018-1000880","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000880","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000880","date":"2026-10-08","epss":0.04056,"percentile":0.90389}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html","http://www.securityfocus.com/bid/106324","https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909","https://github.com/libarchive/libarchive/pull/1105","https://github.com/libarchive/libarchive/pull/1105/commits/9c84b7426660c09c18cc349f6d70b5f8168b5680","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/","https://usn.ubuntu.com/3859-1/","https://www.debian.org/security/2018/dsa-4360"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000880","description":"libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploitable via the victim must open a specially crafted WARC file."}]},{"artifact":{"id":"c5f7168719c595ce","cpes":["cpe:2.3:a:procps-ng:procps-ng:3.3.15-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:procps-ng:procps_ng:3.3.15-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:procps_ng:procps-ng:3.3.15-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:procps_ng:procps_ng:3.3.15-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:procps:procps-ng:3.3.15-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:procps:procps_ng:3.3.15-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:procps-ng:3.3.15-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:procps_ng:3.3.15-14.el8:*:*:*:*:*:*:*"],"name":"procps-ng","purl":"pkg:rpm/redhat/procps-ng@3.3.15-14.el8?arch=x86_64&distro=rhel-8.10&upstream=procps-ng-3.3.15-14.el8.src.rpm","type":"rpm","version":"3.3.15-14.el8","language":"","licenses":["GPL+ and GPLv2 and GPLv2+ and GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1121","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"procps-ng","version":"0:3.3.15-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-1121","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1121","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1121","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1121","date":"2026-10-08","epss":0.04189,"percentile":0.90675}],"risk":1.4452049999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-1121","description":"Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries."},"relatedVulnerabilities":[{"id":"CVE-2018-1121","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.9,"impactScore":2.6,"exploitabilityScore":1.4},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1121","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2018-1121","cwe":"CWE-362","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1121","date":"2026-10-08","epss":0.04189,"percentile":0.90675}],"urls":["http://seclists.org/oss-sec/2018/q2/122","http://www.securityfocus.com/bid/104214","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1121","https://www.exploit-db.com/exploits/44806/","https://www.qualys.com/2018/05/17/procps-ng-audit-report-advisory.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1121","description":"procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() returns PID entries in ascending numeric order, a process occupying a high PID can use inotify events to determine when the process list is being scanned, and fork/exec to obtain a lower PID, thus avoiding enumeration. An unprivileged attacker can hide a process from procps-ng's utilities by exploiting a race condition in reading /proc/PID entries. This vulnerability affects procps and procps-ng up to version 3.3.15, newer versions might be affected also."}]},{"artifact":{"id":"4a3f1224a67c1b93","cpes":["cpe:2.3:a:apache:commons-lang3:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_lang3:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:lang3:3.12.0:*:*:*:*:*:*:*"],"name":"commons-lang3","purl":"pkg:maven/org.apache.commons/commons-lang3@3.12.0","type":"java-archive","version":"3.12.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.apache.commons","virtualPath":"/usr/share/java/kafka/commons-lang3-3.12.0.jar","manifestName":"","pomArtifactID":"commons-lang3","archiveDigests":[{"value":"c6842c86792ff03b9f1d1fe2aab8dc23aa6c6f0e","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/commons-lang3-3.12.0.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/commons-lang3-3.12.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.18.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j288-q9x7-2f5v","versionConstraint":">=3.0,<3.18.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.commons:commons-lang3","version":"3.12.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j288-q9x7-2f5v","fix":{"state":"fixed","versions":["3.18.0"],"available":[{"date":"2025-07-12","kind":"first-observed","version":"3.18.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"risk":1.409325,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48924","https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html","http://www.openwall.com/lists/oss-security/2025/07/11/1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j288-q9x7-2f5v","description":"Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs"},"relatedVulnerabilities":[{"id":"CVE-2025-48924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"urls":["https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","http://www.openwall.com/lists/oss-security/2025/07/11/1","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924","description":"Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.\n\nThe methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a \nStackOverflowError could cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-39537","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-39537","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-08","epss":0.03231,"percentile":0.87888}],"risk":1.373175,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-39537","description":"A heap overflow vulnerability has been identified in the ncurses package, particularly in the \"tic\". This flaw results from a lack of proper bounds checking during input processing. By exploiting this boundary error, an attacker can create a malicious file, deceive the victim into opening it using the affected software, and initiate an out-of-bounds write, potentially impacting system availability."},"relatedVulnerabilities":[{"id":"CVE-2021-39537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-08","epss":0.03231,"percentile":0.87888}],"urls":["http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup","http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/43","http://seclists.org/fulldisclosure/2022/Oct/45","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html","https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html","https://security.netapp.com/advisory/ntap-20230427-0012/","https://support.apple.com/kb/HT213443","https://support.apple.com/kb/HT213444","https://support.apple.com/kb/HT213488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-39537","description":"An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-39537","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-39537","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-08","epss":0.03231,"percentile":0.87888}],"risk":1.373175,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-39537","description":"A heap overflow vulnerability has been identified in the ncurses package, particularly in the \"tic\". This flaw results from a lack of proper bounds checking during input processing. By exploiting this boundary error, an attacker can create a malicious file, deceive the victim into opening it using the affected software, and initiate an out-of-bounds write, potentially impacting system availability."},"relatedVulnerabilities":[{"id":"CVE-2021-39537","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-39537","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-39537","date":"2026-10-08","epss":0.03231,"percentile":0.87888}],"urls":["http://cvsweb.netbsd.org/bsdweb.cgi/pkgsrc/devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c?rev=1.1&content-type=text/x-cvsweb-markup","http://seclists.org/fulldisclosure/2022/Oct/28","http://seclists.org/fulldisclosure/2022/Oct/41","http://seclists.org/fulldisclosure/2022/Oct/43","http://seclists.org/fulldisclosure/2022/Oct/45","https://lists.debian.org/debian-lts-announce/2023/12/msg00004.html","https://lists.gnu.org/archive/html/bug-ncurses/2020-08/msg00006.html","https://lists.gnu.org/archive/html/bug-ncurses/2021-10/msg00023.html","https://security.netapp.com/advisory/ntap-20230427-0012/","https://support.apple.com/kb/HT213443","https://support.apple.com/kb/HT213444","https://support.apple.com/kb/HT213488"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-39537","description":"An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-0727","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-0727","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0727","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-0727","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0727","date":"2026-10-08","epss":0.03187,"percentile":0.877}],"risk":1.3544750000000003,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-0727","description":"A flaw was found in OpenSSL. The optional ContentInfo fields can be set to null, even if the \"type\" is a valid value, which can lead to a null dereference error that may cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2024-0727","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0727","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-0727","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0727","date":"2026-10-08","epss":0.03187,"percentile":0.877}],"urls":["https://github.com/openssl/openssl/commit/09df4395b5071217b76dc7d3d2e630eb8c5a79c2","https://github.com/openssl/openssl/commit/775acfdbd0c6af9ac855f34969cdab0c0c90844a","https://github.com/openssl/openssl/commit/d135eeab8a5dbf72b3da5240bab9ddb7678dbd2c","https://github.openssl.org/openssl/extended-releases/commit/03b3941d60c4bce58fab69a0c22377ab439bc0e8","https://github.openssl.org/openssl/extended-releases/commit/aebaa5883e31122b404e450732dc833dc9dee539","https://www.openssl.org/news/secadv/20240125.txt","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240208-0006/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-277137.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0727","description":"Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL\nto crash leading to a potential Denial of Service attack\n\nImpact summary: Applications loading files in the PKCS12 format from untrusted\nsources might terminate abruptly.\n\nA file in PKCS12 format can contain certificates and keys and may come from an\nuntrusted source. The PKCS12 specification allows certain fields to be NULL, but\nOpenSSL does not correctly check for this case. This can lead to a NULL pointer\ndereference that results in OpenSSL crashing. If an application processes PKCS12\nfiles from an untrusted source using the OpenSSL APIs then that application will\nbe vulnerable to this issue.\n\nOpenSSL APIs that are vulnerable to this are: PKCS12_parse(),\nPKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes()\nand PKCS12_newpass().\n\nWe have also fixed a similar issue in SMIME_write_PKCS7(). However since this\nfunction is related to writing data we do not consider it security significant.\n\nThe FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6129","versionConstraint":">= 3.0.0, < 3.0.13||>= 3.1.0, < 3.1.5||>= 3.2.0, < 3.2.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6129","fix":{"state":"fixed","versions":["3.0.13","3.1.5","3.2.1"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"3.0.13"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.5"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6129","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-6129","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-6129","date":"2026-10-08","epss":0.02323,"percentile":0.82964}],"risk":1.3357249999999998,"urls":["https://github.com/openssl/openssl/commit/050d26383d4e264966fb83428e72d5d48f402d35","https://github.com/openssl/openssl/commit/5b139f95c9a47a55a0c54100f3837b1eee942b04","https://github.com/openssl/openssl/commit/f3fc5808fe9ff74042d639839610d03b8fdcc015","https://www.openssl.org/news/secadv/20240109.txt","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://security.netapp.com/advisory/ntap-20240216-0009/","https://security.netapp.com/advisory/ntap-20240426-0008/","https://security.netapp.com/advisory/ntap-20240426-0013/","https://security.netapp.com/advisory/ntap-20240503-0011/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6129","description":"Issue summary: The POLY1305 MAC (message authentication code) implementation\ncontains a bug that might corrupt the internal state of applications running\non PowerPC CPU based platforms if the CPU provides vector instructions.\n\nImpact summary: If an attacker can influence whether the POLY1305 MAC\nalgorithm is used, the application state might be corrupted with various\napplication dependent consequences.\n\nThe POLY1305 MAC (message authentication code) implementation in OpenSSL for\nPowerPC CPUs restores the contents of vector registers in a different order\nthan they are saved. Thus the contents of some of these vector registers\nare corrupted when returning to the caller. The vulnerable code is used only\non newer PowerPC processors supporting the PowerISA 2.07 instructions.\n\nThe consequences of this kind of internal application state corruption can\nbe various - from no consequences, if the calling application does not\ndepend on the contents of non-volatile XMM registers at all, to the worst\nconsequences, where the attacker could get complete control of the application\nprocess. However unless the compiler uses the vector registers for storing\npointers, the most likely consequence, if any, would be an incorrect result\nof some application dependent calculations or a crash leading to a denial of\nservice.\n\nThe POLY1305 MAC algorithm is most frequently used as part of the\nCHACHA20-POLY1305 AEAD (authenticated encryption with associated data)\nalgorithm. The most common usage of this AEAD cipher is with TLS protocol\nversions 1.2 and 1.3. If this cipher is enabled on the server a malicious\nclient can influence whether this AEAD cipher is used. This implies that\nTLS server applications using OpenSSL can be potentially impacted. However\nwe are currently not aware of any concrete application that would be affected\nby this issue therefore we consider this a Low severity security issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-21.el8_10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-49796","versionConstraint":"< 0:2.9.7-21.el8_10.1 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-49796","fix":{"state":"fixed","versions":["0:2.9.7-21.el8_10.1"],"available":[{"date":"2025-07-10","kind":"first-observed","version":"0:2.9.7-21.el8_10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49796","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-49796","date":"2026-10-08","epss":0.01558,"percentile":0.74454}],"risk":1.29314,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10698","link":"https://access.redhat.com/errata/RHSA-2025:10698"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-49796","description":"A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory."},"relatedVulnerabilities":[{"id":"CVE-2025-49796","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49796","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-49796","date":"2026-10-08","epss":0.01558,"percentile":0.74454}],"urls":["https://access.redhat.com/errata/RHSA-2025:10630","https://access.redhat.com/errata/RHSA-2025:10698","https://access.redhat.com/errata/RHSA-2025:10699","https://access.redhat.com/errata/RHSA-2025:11580","https://access.redhat.com/errata/RHSA-2025:12098","https://access.redhat.com/errata/RHSA-2025:12099","https://access.redhat.com/errata/RHSA-2025:12199","https://access.redhat.com/errata/RHSA-2025:12237","https://access.redhat.com/errata/RHSA-2025:12239","https://access.redhat.com/errata/RHSA-2025:12240","https://access.redhat.com/errata/RHSA-2025:12241","https://access.redhat.com/errata/RHSA-2025:13267","https://access.redhat.com/errata/RHSA-2025:13335","https://access.redhat.com/errata/RHSA-2025:15397","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:18217","https://access.redhat.com/errata/RHSA-2025:18218","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:18240","https://access.redhat.com/errata/RHSA-2025:19020","https://access.redhat.com/errata/RHSA-2025:19041","https://access.redhat.com/errata/RHSA-2025:19046","https://access.redhat.com/errata/RHSA-2025:19894","https://access.redhat.com/errata/RHSA-2025:21913","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2025-49796","https://bugzilla.redhat.com/show_bug.cgi?id=2372385","https://gitlab.gnome.org/GNOME/libxml2/-/issues/933","https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-49796","description":"A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory."}]},{"artifact":{"id":"4afeeed91e127737","cpes":["cpe:2.3:a:libgcc:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20657","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-20657","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20657","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20657","date":"2026-10-08","epss":0.04004,"percentile":0.9028}],"risk":1.2612599999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-20657","description":"A vulnerability was found in the demangle_template function in GNU libiberty, as distributed in GNU Binutils, where a memory leak could occur, a specially crafted file could cause the application to consume excessive memory, potentially leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2018-20657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20657","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20657","date":"2026-10-08","epss":0.04004,"percentile":0.9028}],"urls":["http://www.securityfocus.com/bid/106444","https://access.redhat.com/errata/RHSA-2019:3352","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539","https://support.f5.com/csp/article/K62602089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20657","description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698."}]},{"artifact":{"id":"4fd2ded12bcd7931","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20657","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-20657","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20657","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20657","date":"2026-10-08","epss":0.04004,"percentile":0.9028}],"risk":1.2612599999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-20657","description":"A vulnerability was found in the demangle_template function in GNU libiberty, as distributed in GNU Binutils, where a memory leak could occur, a specially crafted file could cause the application to consume excessive memory, potentially leading to a crash."},"relatedVulnerabilities":[{"id":"CVE-2018-20657","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20657","cwe":"CWE-772","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20657","date":"2026-10-08","epss":0.04004,"percentile":0.9028}],"urls":["http://www.securityfocus.com/bid/106444","https://access.redhat.com/errata/RHSA-2019:3352","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539","https://support.f5.com/csp/article/K62602089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20657","description":"The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:1.1.1k-16.el8_6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-4741","versionConstraint":"< 1:1.1.1k-16.el8_6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-4741","fix":{"state":"fixed","versions":["1:1.1.1k-16.el8_6"],"available":[{"date":"2026-06-17","kind":"first-observed","version":"1:1.1.1k-16.el8_6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-4741","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-4741","date":"2026-10-08","epss":0.02925,"percentile":0.86654}],"risk":1.25775,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:26275","link":"https://access.redhat.com/errata/RHSA-2026:26275"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-4741","description":"A use-after-free vulnerability was found in OpenSSL. Calling the OpenSSL API SSL_free_buffers function may cause memory to be accessed that was previously freed in some situations."},"relatedVulnerabilities":[{"id":"CVE-2024-4741","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-4741","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-4741","date":"2026-10-08","epss":0.02925,"percentile":0.86654}],"urls":["https://github.com/openssl/openssl/commit/704f725b96aa373ee45ecfb23f6abfe8be8d9177","https://github.com/openssl/openssl/commit/b3f0eb0a295f58f16ba43ba99dad70d4ee5c437d","https://github.com/openssl/openssl/commit/c88c3de51020c37e8706bf7a682a162593053aac","https://github.com/openssl/openssl/commit/e5093133c35ca82874ad83697af76f4b0f7e3bd8","https://github.openssl.org/openssl/extended-releases/commit/f7a045f3143fc6da2ee66bf52d8df04829590dd4","https://www.openssl.org/news/secadv/20240528.txt","https://lists.debian.org/debian-lts-announce/2024/10/msg00033.html","https://lists.debian.org/debian-lts-announce/2024/11/msg00000.html","https://security.netapp.com/advisory/ntap-20240621-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-4741","description":"Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause\nmemory to be accessed that was previously freed in some situations\n\nImpact summary: A use after free can have a range of potential consequences such\nas the corruption of valid data, crashes or execution of arbitrary code.\nHowever, only applications that directly call the SSL_free_buffers function are\naffected by this issue. Applications that do not call this function are not\nvulnerable. Our investigations indicate that this function is rarely used by\napplications.\n\nThe SSL_free_buffers function is used to free the internal OpenSSL buffer used\nwhen processing an incoming record from the network. The call is only expected\nto succeed if the buffer is not currently in use. However, two scenarios have\nbeen identified where the buffer is freed even when still in use.\n\nThe first scenario occurs where a record header has been received from the\nnetwork and processed by OpenSSL, but the full record body has not yet arrived.\nIn this case calling SSL_free_buffers will succeed even though a record has only\nbeen partially processed and the buffer is still in use.\n\nThe second scenario occurs where a full record containing application data has\nbeen received and processed by OpenSSL but the application has only read part of\nthis data. Again a call to SSL_free_buffers will succeed even though the buffer\nis still in use.\n\nWhile these scenarios could occur accidentally during normal operation a\nmalicious attacker could attempt to engineer a stituation where this occurs.\nWe are not aware of this issue being actively exploited.\n\nThe FIPS modules in 3.3, 3.2, 3.1 and 3.0 are not affected by this issue."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.13"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-6237","versionConstraint":">= 3.0.0, < 3.0.13||>= 3.1.0, < 3.1.5||>= 3.2.0, < 3.2.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-6237","fix":{"state":"fixed","versions":["3.0.13","3.1.5","3.2.1"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"3.0.13"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.5"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-6237","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2023-6237","date":"2026-10-08","epss":0.02303,"percentile":0.82806}],"risk":1.255135,"urls":["https://github.com/openssl/openssl/commit/0b0f7abfb37350794a4b8960fafc292cd5d1b84d","https://github.com/openssl/openssl/commit/18c02492138d1eb8b6548cb26e7b625fb2414a2a","https://github.com/openssl/openssl/commit/a830f551557d3d66a84bbb18a5b889c640c36294","https://www.openssl.org/news/secadv/20240115.txt","http://www.openwall.com/lists/oss-security/2024/03/11/1","https://security.netapp.com/advisory/ntap-20240531-0007/","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-331112.html","https://cert-portal.siemens.com/productcert/html/ssa-769027.html","https://cert-portal.siemens.com/productcert/html/ssa-915275.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-6237","description":"Issue summary: Checking excessively long invalid RSA public keys may take\na long time.\n\nImpact summary: Applications that use the function EVP_PKEY_public_check()\nto check RSA public keys may experience long delays. Where the key that\nis being checked has been obtained from an untrusted source this may lead\nto a Denial of Service.\n\nWhen function EVP_PKEY_public_check() is called on RSA public keys,\na computation is done to confirm that the RSA modulus, n, is composite.\nFor valid RSA keys, n is a product of two or more large primes and this\ncomputation completes quickly. However, if n is an overly large prime,\nthen this computation would take a long time.\n\nAn application that calls EVP_PKEY_public_check() and supplies an RSA key\nobtained from an untrusted source could be vulnerable to a Denial of Service\nattack.\n\nThe function EVP_PKEY_public_check() is not called from other OpenSSL\nfunctions however it is called from the OpenSSL pkey command line\napplication. For that reason that application is also vulnerable if used\nwith the '-pubin' and '-check' options on untrusted data.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-1.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-28757","versionConstraint":"< 0:2.5.0-1.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-28757","fix":{"state":"fixed","versions":["0:2.5.0-1.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.5.0-1.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28757","date":"2026-10-08","epss":0.02006,"percentile":0.8022}],"risk":1.25375,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:21776","link":"https://access.redhat.com/errata/RHSA-2025:21776"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-28757","description":"An XML Entity Expansion flaw was found in libexpat. This flaw allows an attacker to cause a denial of service when there is an isolated use of external parsers."},"relatedVulnerabilities":[{"id":"CVE-2024-28757","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2024-28757","cwe":"CWE-776","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-28757","date":"2026-10-08","epss":0.02006,"percentile":0.8022}],"urls":["http://www.openwall.com/lists/oss-security/2024/03/15/1","https://github.com/libexpat/libexpat/issues/839","https://github.com/libexpat/libexpat/pull/842","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/","https://security.netapp.com/advisory/ntap-20240322-0001/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FPLC6WDSRDUYS7F7JWAOVOHFNOUQ43DD/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKJ7V5F6LJCEQJXDBWGT27J7NAP3E3N7/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VK2O34GH43NTHBZBN7G5Y6YKJKPUCTBE/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-28757","description":"libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate)."}]},{"artifact":{"id":"15ab448eaed3b129","cpes":["cpe:2.3:a:libarchive:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.3.3-5.el8?arch=x86_64&distro=rhel-8.10&upstream=libarchive-3.3.3-5.el8.src.rpm","type":"rpm","version":"3.3.3-5.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1000879","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libarchive","version":"0:3.3.3-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-1000879","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000879","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000879","date":"2026-10-08","epss":0.03367,"percentile":0.8841}],"risk":1.228955,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-1000879","description":"A vulnerability was found in libarchive, where a NULL pointer dereference in the archive_acl_from_text_l function in libarchive/archive_acl.c can lead to a denial of service, a remote attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to crash."},"relatedVulnerabilities":[{"id":"CVE-2018-1000879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-1000879","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-1000879","date":"2026-10-08","epss":0.03367,"percentile":0.8841}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00055.html","http://www.securityfocus.com/bid/106324","https://bugs.launchpad.net/ubuntu/+source/libarchive/+bug/1794909","https://github.com/libarchive/libarchive/pull/1105","https://github.com/libarchive/libarchive/pull/1105/commits/15bf44fd2c1ad0e3fd87048b3fcc90c4dcff1175","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBOCC2M6YGPZA6US43YK4INPSJZZHRTG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W645KCLWFDBDGFJHG57WOVXGE62QSIJI/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZVXA7PHINVT6DFF6PRLTDTVTXKDLVHNF/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000879","description":"libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted archive file."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-63076","versionConstraint":">= 3.0.0, < 3.0.22||>= 3.4.0, < 3.4.7||>= 3.5.0, < 3.5.8||>= 3.6.0, < 3.6.4||>= 4.0.0, < 4.0.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-63076","fix":{"state":"fixed","versions":["3.0.22","3.4.7","3.5.8","3.6.4","4.0.2"],"available":[{"date":"2026-08-29","kind":"first-observed","version":"3.0.22"},{"date":"2026-08-29","kind":"first-observed","version":"3.4.7"},{"date":"2026-08-29","kind":"first-observed","version":"3.5.8"},{"date":"2026-08-29","kind":"first-observed","version":"3.6.4"},{"date":"2026-08-29","kind":"first-observed","version":"4.0.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63076","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63076","date":"2026-10-08","epss":0.01602,"percentile":0.75073}],"risk":1.2015,"urls":["https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b","https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e","https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259","https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226","https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63076","description":"Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"1d1d40d939f8dea2","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"30ebb05b6b0fb071dbfcf713017c4a767a97bb9b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.135.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x4gw-5cx5-pgmh","versionConstraint":"<=4.1.134.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-x4gw-5cx5-pgmh","fix":{"state":"fixed","versions":["4.1.135.Final"],"available":[{"date":"2026-06-09","kind":"first-observed","version":"4.1.135.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45416","date":"2026-10-08","epss":0.01576,"percentile":0.74713}],"risk":1.1820000000000002,"urls":["https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-45416"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x4gw-5cx5-pgmh","description":"Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes"},"relatedVulnerabilities":[{"id":"CVE-2026-45416","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-45416","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45416","date":"2026-10-08","epss":0.01576,"percentile":0.74713}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-45416","https://bugzilla.redhat.com/show_bug.cgi?id=2488391","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45416.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45416","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"ec310121cbd5d68c","cpes":["cpe:2.3:a:python:setuptools:71.1.0:*:*:*:*:*:*:*"],"name":"setuptools","purl":"pkg:pypi/setuptools@71.1.0","type":"python","version":"71.1.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/top_level.txt","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"78.1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5rjg-fvgr-3xxf","versionConstraint":"<78.1.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"setuptools","version":"71.1.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-5rjg-fvgr-3xxf","fix":{"state":"fixed","versions":["78.1.1"],"available":[{"date":"2025-05-22","kind":"first-observed","version":"78.1.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"risk":1.16964,"urls":["https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf","https://nvd.nist.gov/vuln/detail/CVE-2025-47273","https://github.com/pypa/setuptools/issues/4946","https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b","https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88","https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html","https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2025-49.yaml"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5rjg-fvgr-3xxf","description":"setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write"},"relatedVulnerabilities":[{"id":"CVE-2025-47273","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"urls":["https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88","https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b","https://github.com/pypa/setuptools/issues/4946","https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf","https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.18"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-9230","versionConstraint":">= 1.0.2, < 1.0.2zm||>= 1.1.1, < 1.1.1zd||>= 3.0.0, < 3.0.18||>= 3.2.0, < 3.2.6||>= 3.3.0, < 3.3.5||>= 3.4.0, < 3.4.3||>= 3.5.0, < 3.5.4 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-9230","fix":{"state":"fixed","versions":["1.0.2zm","1.1.1zd","3.0.18","3.2.6","3.3.5","3.4.3","3.5.4"],"available":[{"date":"2025-10-04","kind":"first-observed","version":"1.0.2zm"},{"date":"2025-10-04","kind":"first-observed","version":"1.1.1zd"},{"date":"2025-10-04","kind":"first-observed","version":"3.0.18"},{"date":"2025-10-04","kind":"first-observed","version":"3.2.6"},{"date":"2025-10-04","kind":"first-observed","version":"3.3.5"},{"date":"2025-10-04","kind":"first-observed","version":"3.4.3"},{"date":"2025-10-04","kind":"first-observed","version":"3.5.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9230","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-9230","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9230","date":"2026-10-08","epss":0.01554,"percentile":0.74399}],"risk":1.1655,"urls":["https://github.com/openssl/openssl/commit/5965ea5dd6960f36d8b7f74f8eac67a8eb8f2b45","https://github.com/openssl/openssl/commit/9e91358f365dee6c446dcdcdb01c04d2743fd280","https://github.com/openssl/openssl/commit/a79c4ce559c6a3a8fd4109e9f33c1185d5bf2def","https://github.com/openssl/openssl/commit/b5282d677551afda7d20e9c00e09561b547b2dfd","https://github.com/openssl/openssl/commit/bae259a211ada6315dc50900686daaaaaa55f482","https://github.openssl.org/openssl/extended-releases/commit/c2b96348bfa662f25f4fabf81958ae822063dae3","https://github.openssl.org/openssl/extended-releases/commit/dfbaf161d8dafc1132dd88cd48ad990ed9b4c8ba","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://lists.debian.org/debian-lts-announce/2025/10/msg00001.html","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9230","description":"Issue summary: An application trying to decrypt CMS messages encrypted using\npassword based encryption can trigger an out-of-bounds read and write.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application. The out-of-bounds write can cause\na memory corruption which can have various consequences including\na Denial of Service or Execution of attacker-supplied code.\n\nAlthough the consequences of a successful exploit of this vulnerability\ncould be severe, the probability that the attacker would be able to\nperform it is low. Besides, password based (PWRI) encryption support in CMS\nmessages is very rarely used. For that reason the issue was assessed as\nModerate severity according to our Security Policy.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"fa819346ba1b9bc6","cpes":["cpe:2.3:a:systemd:systemd:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:rpm/redhat/systemd@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-20839","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"0:239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-20839","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":3.6,"exploitabilityScore":0.7},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20839","date":"2026-10-08","epss":0.02478,"percentile":0.84082}],"risk":1.15227,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-20839","description":"The issue arises from the way systemd handles user passwords during the boot process. Specifically, passwords entered on the console during the system boot (e.g., for unlocking encrypted disks or logging in) could be logged in plaintext if certain conditions are met."},"relatedVulnerabilities":[{"id":"CVE-2018-20839","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":3.6,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20839","date":"2026-10-08","epss":0.02478,"percentile":0.84082}],"urls":["http://www.securityfocus.com/bid/108389","https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993","https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f","https://github.com/systemd/systemd/pull/12378","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://security.netapp.com/advisory/ntap-20190530-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20839","description":"systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled."}]},{"artifact":{"id":"35ec2c60a4c27ac2","cpes":["cpe:2.3:a:systemd-libs:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd-libs:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd-libs","purl":"pkg:rpm/redhat/systemd-libs@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"239-82.el8_10.5"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20839","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-20839","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":3.6,"exploitabilityScore":0.7},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20839","date":"2026-10-08","epss":0.02478,"percentile":0.84082}],"risk":1.15227,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-20839","description":"The issue arises from the way systemd handles user passwords during the boot process. Specifically, passwords entered on the console during the system boot (e.g., for unlocking encrypted disks or logging in) could be logged in plaintext if certain conditions are met."},"relatedVulnerabilities":[{"id":"CVE-2018-20839","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":3.6,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20839","date":"2026-10-08","epss":0.02478,"percentile":0.84082}],"urls":["http://www.securityfocus.com/bid/108389","https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993","https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f","https://github.com/systemd/systemd/pull/12378","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://security.netapp.com/advisory/ntap-20190530-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20839","description":"systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled."}]},{"artifact":{"id":"3072771f0e906f1d","cpes":["cpe:2.3:a:systemd-pam:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd-pam:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd-pam","purl":"pkg:rpm/redhat/systemd-pam@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"239-82.el8_10.5"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20839","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-20839","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":3.6,"exploitabilityScore":0.7},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20839","date":"2026-10-08","epss":0.02478,"percentile":0.84082}],"risk":1.15227,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-20839","description":"The issue arises from the way systemd handles user passwords during the boot process. Specifically, passwords entered on the console during the system boot (e.g., for unlocking encrypted disks or logging in) could be logged in plaintext if certain conditions are met."},"relatedVulnerabilities":[{"id":"CVE-2018-20839","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":3.6,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-20839","date":"2026-10-08","epss":0.02478,"percentile":0.84082}],"urls":["http://www.securityfocus.com/bid/108389","https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1803993","https://github.com/systemd/systemd/commit/9725f1a10f80f5e0ae7d9b60547458622aeb322f","https://github.com/systemd/systemd/pull/12378","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E","https://security.netapp.com/advisory/ntap-20190530-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20839","description":"systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mode) check is mishandled."}]},{"artifact":{"id":"8ab0f0f754c8b1e4","cpes":["cpe:2.3:a:libgcrypt:libgcrypt:1.8.5-7.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcrypt:1.8.5-7.el8_6:*:*:*:*:*:*:*"],"name":"libgcrypt","purl":"pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=rhel-8.10&upstream=libgcrypt-1.8.5-7.el8_6.src.rpm","type":"rpm","version":"1.8.5-7.el8_6","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-12904","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libgcrypt","version":"0:1.8.5-7.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-12904","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12904","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12904","date":"2026-10-08","epss":0.02063,"percentile":0.80775}],"risk":1.124335,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-12904","description":"[Disputed] A vulnerability has been identified in Libgcrypt due to a flaw in its C implementation of AES. This vulnerability enables a remote attacker to perform a flush-and-reload side-channel attack, potentially accessing sensitive information. The vulnerability arises from the availability of physical addresses to other processes, particularly on platforms lacking an assembly-language implementation."},"relatedVulnerabilities":[{"id":"CVE-2019-12904","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-12904","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-12904","date":"2026-10-08","epss":0.02063,"percentile":0.80775}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00049.html","https://dev.gnupg.org/T4541","https://github.com/gpg/libgcrypt/commit/a4c561aab1014c3630bc88faf6f5246fee16b020","https://github.com/gpg/libgcrypt/commit/daedbbb5541cd8ecda1459d3b843ea4d92788762","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-12904","description":"In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack"}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28388","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-28388","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"risk":1.1129450000000003,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28388","description":"A flaw was found in OpenSSL. When processing a malformed delta Certificate Revocation List (CRL) that lacks a required CRL Number extension, a NULL pointer dereference can occur. This vulnerability can be exploited by a remote attacker who provides a specially crafted delta CRL to an application that has delta CRL processing enabled, leading to a Denial of Service (DoS) for the application."},"relatedVulnerabilities":[{"id":"CVE-2026-28388","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28388","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28388","date":"2026-10-08","epss":0.02501,"percentile":0.84231}],"urls":["https://github.com/openssl/openssl/commit/59c3b3158553ab53275bbbccca5cb305d591cf2e","https://github.com/openssl/openssl/commit/5a0b4930779cd2408880979db765db919da55139","https://github.com/openssl/openssl/commit/602542f2c0c2d5edb47128f93eac10b62aeeefb3","https://github.com/openssl/openssl/commit/a9d187dd1000130100fa7ab915f8513532cb3bb8","https://github.com/openssl/openssl/commit/d3a901e8d9f021f3e67d6cfbc12e768129862726","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28388","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28389","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-28389","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"risk":1.0835750000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28389","description":"A flaw was found in OpenSSL. A remote attacker could exploit this by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message with KeyAgreeRecipientInfo. This vulnerability arises because the software attempts to process an optional field without verifying its existence, leading to a NULL pointer dereference. This can result in a Denial of Service (DoS) for applications that handle untrusted CMS data."},"relatedVulnerabilities":[{"id":"CVE-2026-28389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28389","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28389","date":"2026-10-08","epss":0.02435,"percentile":0.83783}],"urls":["https://github.com/openssl/openssl/commit/16cea4188e0ea567deb4f93f85902247e67384f5","https://github.com/openssl/openssl/commit/785cbf7ea3b5a6f5adf0c1ccb92b79d89c35c616","https://github.com/openssl/openssl/commit/7b5274e812400cacb6f3be4c2df5340923fa807f","https://github.com/openssl/openssl/commit/c6725634e089eb2b634b10ede33944be7248172a","https://github.com/openssl/openssl/commit/f80f83bc5fd036bc47d773e8b15a001e2b4ce686","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28389","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4517","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4517","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":5.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"risk":1.07965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4517","description":"A flaw was found in the CPython tarfile module. This vulnerability allows arbitrary filesystem writes outside the extraction directory via extracting untrusted tar archives using the TarFile.extractall() or TarFile.extract() methods with the extraction filter parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4517","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4517","description":"Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4517","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4517","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":5.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"risk":1.07965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4517","description":"A flaw was found in the CPython tarfile module. This vulnerability allows arbitrary filesystem writes outside the extraction directory via extracting untrusted tar archives using the TarFile.extractall() or TarFile.extract() methods with the extraction filter parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4517","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4517","description":"Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-4517","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4517","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":5.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"risk":1.07965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4517","description":"A flaw was found in the CPython tarfile module. This vulnerability allows arbitrary filesystem writes outside the extraction directory via extracting untrusted tar archives using the TarFile.extractall() or TarFile.extract() methods with the extraction filter parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4517","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4517","description":"Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4517","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4517","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":5.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"risk":1.07965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4517","description":"A flaw was found in the CPython tarfile module. This vulnerability allows arbitrary filesystem writes outside the extraction directory via extracting untrusted tar archives using the TarFile.extractall() or TarFile.extract() methods with the extraction filter parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4517","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4517","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4517","date":"2026-10-08","epss":0.0143,"percentile":0.72229}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4517","description":"Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19189","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19189","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-08","epss":0.02234,"percentile":0.82244}],"risk":1.06115,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19189","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2020-19189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-08","epss":0.02234,"percentile":0.82244}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md","https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19189","description":"Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19189","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19189","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-08","epss":0.02234,"percentile":0.82244}],"risk":1.06115,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19189","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2020-19189","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19189","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19189","date":"2026-10-08","epss":0.02234,"percentile":0.82244}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc5.md","https://lists.debian.org/debian-lts-announce/2023/09/msg00033.html","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19189","description":"Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4138","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4138","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"risk":1.0387499999999998,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4138","description":"A flaw was found in the Python tarfile module. This vulnerability allows attackers to bypass extraction filters, enabling symlink targets to escape the destination directory and allowing unauthorized modification of file metadata via the use of TarFile.extract() or TarFile.extractall() with the filter= parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4138","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4138","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4138","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4138","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"risk":1.0387499999999998,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4138","description":"A flaw was found in the Python tarfile module. This vulnerability allows attackers to bypass extraction filters, enabling symlink targets to escape the destination directory and allowing unauthorized modification of file metadata via the use of TarFile.extract() or TarFile.extractall() with the filter= parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4138","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4138","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-4138","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4138","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"risk":1.0387499999999998,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4138","description":"A flaw was found in the Python tarfile module. This vulnerability allows attackers to bypass extraction filters, enabling symlink targets to escape the destination directory and allowing unauthorized modification of file metadata via the use of TarFile.extract() or TarFile.extractall() with the filter= parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4138","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4138","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4138","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4138","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"risk":1.0387499999999998,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4138","description":"A flaw was found in the Python tarfile module. This vulnerability allows attackers to bypass extraction filters, enabling symlink targets to escape the destination directory and allowing unauthorized modification of file metadata via the use of TarFile.extract() or TarFile.extractall() with the filter= parameter set to \"data\" or \"tar\"."},"relatedVulnerabilities":[{"id":"CVE-2025-4138","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4138","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4138","date":"2026-10-08","epss":0.01385,"percentile":0.71386}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4138","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"1d1d40d939f8dea2","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"30ebb05b6b0fb071dbfcf713017c4a767a97bb9b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.135.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3qp7-7mw8-wx86","versionConstraint":"<=4.1.134.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3qp7-7mw8-wx86","fix":{"state":"fixed","versions":["4.1.135.Final"],"available":[{"date":"2026-06-09","kind":"first-observed","version":"4.1.135.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44249","date":"2026-10-08","epss":0.01291,"percentile":0.69378}],"risk":1.00698,"urls":["https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://nvd.nist.gov/vuln/detail/CVE-2026-44249"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3qp7-7mw8-wx86","description":"Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking"},"relatedVulnerabilities":[{"id":"CVE-2026-44249","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44249","cwe":"CWE-284","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44249","cwe":"CWE-1287","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44249","date":"2026-10-08","epss":0.01291,"percentile":0.69378}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48124","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-44249","https://bugzilla.redhat.com/show_bug.cgi?id=2488081","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44249","description":"Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"0bc0698cf4cd83dd","cpes":["cpe:2.3:a:iputils:iputils:20180629-11.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:iputils:20180629-11.el8:*:*:*:*:*:*:*"],"name":"iputils","purl":"pkg:rpm/redhat/iputils@20180629-11.el8?arch=x86_64&distro=rhel-8.10&upstream=iputils-20180629-11.el8.src.rpm","type":"rpm","version":"20180629-11.el8","language":"","licenses":["BSD and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-47268","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"iputils","version":"0:20180629-11.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-47268","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47268","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-47268","date":"2026-10-08","epss":0.01745,"percentile":0.77093}],"risk":1.003375,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-47268","description":"A flaw was found in iputils ping, where a signed integer overflow occurs in timestamp multiplication. This issue could lead to incorrect timestamp calculations or denial of service when processing crafted ICMP Echo Reply packets."},"relatedVulnerabilities":[{"id":"CVE-2025-47268","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47268","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-47268","date":"2026-10-08","epss":0.01745,"percentile":0.77093}],"urls":["https://bugzilla.suse.com/show_bug.cgi?id=1242300","https://github.com/Zephkek/ping-rtt-overflow/","https://github.com/iputils/iputils/commit/070cfacd7348386173231fb16fad4983d4e6ae40","https://github.com/iputils/iputils/issues/584","https://github.com/iputils/iputils/pull/585","https://github.com/iputils/iputils/releases/tag/20250602"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47268","description":"ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication."}]},{"artifact":{"id":"1ed86a8e00e9ac03","cpes":["cpe:2.3:a:libzstd:libzstd:1.4.4-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libzstd:1.4.4-1.el8:*:*:*:*:*:*:*"],"name":"libzstd","purl":"pkg:rpm/redhat/libzstd@1.4.4-1.el8?arch=x86_64&distro=rhel-8.10&upstream=zstd-1.4.4-1.el8.src.rpm","type":"rpm","version":"1.4.4-1.el8","language":"","licenses":["BSD and GPLv2"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zstd","version":"1.4.4-1.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-4899","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"zstd","version":"1.4.4-1.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2022-4899","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4899","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-4899","cwe":"CWE-400","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4899","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4899","date":"2026-10-08","epss":0.01588,"percentile":0.7488}],"risk":0.9924999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-4899","description":"A vulnerability was found in zstd. This flaw allows an attacker to supply an empty string as an argument to the command line tool to cause a buffer overrun."},"relatedVulnerabilities":[{"id":"CVE-2022-4899","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-4899","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2022-4899","cwe":"CWE-400","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2022-4899","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-4899","date":"2026-10-08","epss":0.01588,"percentile":0.7488}],"urls":["https://github.com/facebook/zstd/issues/3200","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C63HAGVLQA6FJNDCHR7CNZZL6VSLILB2/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JEHRBBYYTPA4DETOM5XAKGCP37NUTLOA/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QYLDK6ODVC4LJSDULLX6Q2YHTFOWABCN/","https://security.netapp.com/advisory/ntap-20230725-0005/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-4899","description":"A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-34180","versionConstraint":">= 1.0.2, < 1.0.2zq||>= 1.1.1, < 1.1.1zh||>= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-34180","fix":{"state":"fixed","versions":["1.0.2zq","1.1.1zh","3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"1.0.2zq"},{"date":"2026-06-11","kind":"first-observed","version":"1.1.1zh"},{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"risk":0.9832500000000001,"urls":["https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d","https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83","https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff","https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43","https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7a0e2caa95ccb2be","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:http:9.4.57.v20241219:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","type":"java-archive","version":"9.4.57.v20241219","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0, https://www.eclipse.org/org/documents/epl-v10.php"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/usr/share/java/kafka/jetty-http-9.4.57.v20241219.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"c7a3a9c599346708894cf355e03105937f45f427","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jetty-http-9.4.57.v20241219.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jetty-http-9.4.57.v20241219.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.4.60"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-355h-qmc2-wpwf","versionConstraint":">=9.4.0,<=9.4.59 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-355h-qmc2-wpwf","fix":{"state":"fixed","versions":["9.4.60"],"available":[{"date":"2026-04-15","kind":"first-observed","version":"9.4.60"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-2332","date":"2026-10-08","epss":0.01305,"percentile":0.69668}],"risk":0.972225,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://nvd.nist.gov/vuln/detail/CVE-2026-2332","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://w4ke.info/2025/06/18/funky-chunks.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://access.redhat.com/security/cve/CVE-2026-2332","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:10175"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-355h-qmc2-wpwf","description":"Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-2332","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-2332","date":"2026-10-08","epss":0.01305,"percentile":0.69668}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-2332","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332","description":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request."}]},{"artifact":{"id":"5dd5ead7aa827e89","cpes":["cpe:2.3:a:apache:zookeeper:3.8.4:*:*:*:*:*:*:*"],"name":"zookeeper","purl":"pkg:maven/org.apache.zookeeper/zookeeper@3.8.4","type":"java-archive","version":"3.8.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.zookeeper","virtualPath":"/usr/share/java/cp-base-new/zookeeper-3.8.4.jar","manifestName":"","pomArtifactID":"zookeeper","archiveDigests":[{"value":"6638e37b887b5a279044afbdc9928e19f678eb2e","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/zookeeper-3.8.4.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/zookeeper-3.8.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.8.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-crhr-qqj8-rpxc","versionConstraint":">=3.8.0,<3.8.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.zookeeper:zookeeper","version":"3.8.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-crhr-qqj8-rpxc","fix":{"state":"fixed","versions":["3.8.6"],"available":[{"date":"2026-03-10","kind":"first-observed","version":"3.8.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24308","cwe":"CWE-532","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24308","cwe":"CWE-117","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24308","date":"2026-10-08","epss":0.01197,"percentile":0.67207}],"risk":0.9695699999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-24308","https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdr","http://www.openwall.com/lists/oss-security/2026/03/07/5","https://github.com/apache/zookeeper/releases/tag/release-3.8.6","https://github.com/apache/zookeeper/releases/tag/release-3.9.5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-crhr-qqj8-rpxc","description":"Apache ZooKeeper has improper handling of configuration values"},"relatedVulnerabilities":[{"id":"CVE-2026-24308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24308","cwe":"CWE-532","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24308","cwe":"CWE-117","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24308","date":"2026-10-08","epss":0.01197,"percentile":0.67207}],"urls":["https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdr","http://www.openwall.com/lists/oss-security/2026/03/07/5","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-24308","https://bugzilla.redhat.com/show_bug.cgi?id=2445451","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24308.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24308","description":"Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue."}]},{"artifact":{"id":"b9af4561da4d9058","cpes":["cpe:2.3:a:apache:zookeeper:3.8.4:*:*:*:*:*:*:*"],"name":"zookeeper","purl":"pkg:maven/org.apache.zookeeper/zookeeper@3.8.4","type":"java-archive","version":"3.8.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.zookeeper","virtualPath":"/usr/share/java/kafka/zookeeper-3.8.4.jar","manifestName":"","pomArtifactID":"zookeeper","archiveDigests":[{"value":"6638e37b887b5a279044afbdc9928e19f678eb2e","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/zookeeper-3.8.4.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/zookeeper-3.8.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.8.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-crhr-qqj8-rpxc","versionConstraint":">=3.8.0,<3.8.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.zookeeper:zookeeper","version":"3.8.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-crhr-qqj8-rpxc","fix":{"state":"fixed","versions":["3.8.6"],"available":[{"date":"2026-03-10","kind":"first-observed","version":"3.8.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24308","cwe":"CWE-532","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24308","cwe":"CWE-117","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24308","date":"2026-10-08","epss":0.01197,"percentile":0.67207}],"risk":0.9695699999999999,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-24308","https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdr","http://www.openwall.com/lists/oss-security/2026/03/07/5","https://github.com/apache/zookeeper/releases/tag/release-3.8.6","https://github.com/apache/zookeeper/releases/tag/release-3.9.5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-crhr-qqj8-rpxc","description":"Apache ZooKeeper has improper handling of configuration values"},"relatedVulnerabilities":[{"id":"CVE-2026-24308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24308","cwe":"CWE-532","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24308","cwe":"CWE-117","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24308","date":"2026-10-08","epss":0.01197,"percentile":0.67207}],"urls":["https://lists.apache.org/thread/qng3rtzv2pqkmko4rhv85jfplkyrgqdr","http://www.openwall.com/lists/oss-security/2026/03/07/5","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-24308","https://bugzilla.redhat.com/show_bug.cgi?id=2445451","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24308.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24308","description":"Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue."}]},{"artifact":{"id":"93eed475e569196b","cpes":["cpe:2.3:a:platform-python-pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python-pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"platform-python-pip","purl":"pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20225","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-20225","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20225","date":"2026-10-08","epss":0.0178,"percentile":0.77581}],"risk":0.9612,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-20225","description":"A vulnerability was found in python-pip due to a flaw in the --extra-index-url option, where it installs the version with the highest version number, even if the user intended to obtain a private package from a private index. Exploitation requires that the package does not already exist in the public index, allowing an attacker to place the package there with an arbitrary version number."},"relatedVulnerabilities":[{"id":"CVE-2018-20225","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20225","date":"2026-10-08","epss":0.0178,"percentile":0.77581}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1835736","https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html","https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2%40%3Cgithub.arrow.apache.org%3E","https://pip.pypa.io/en/stable/news/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20225","description":"An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely"}]},{"artifact":{"id":"fa83cdeeda4e9e6a","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20225","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-20225","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20225","date":"2026-10-08","epss":0.0178,"percentile":0.77581}],"risk":0.9612,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-20225","description":"A vulnerability was found in python-pip due to a flaw in the --extra-index-url option, where it installs the version with the highest version number, even if the user intended to obtain a private package from a private index. Exploitation requires that the package does not already exist in the public index, allowing an attacker to place the package there with an arbitrary version number."},"relatedVulnerabilities":[{"id":"CVE-2018-20225","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-20225","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-20225","date":"2026-10-08","epss":0.0178,"percentile":0.77581}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1835736","https://cowlicks.website/posts/arbitrary-code-execution-from-pips-extra-index-url.html","https://lists.apache.org/thread.html/rb1adce798445facd032870d644eb39c4baaf9c4a7dd5477d12bb6ab2%40%3Cgithub.arrow.apache.org%3E","https://pip.pypa.io/en/stable/news/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20225","description":"An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely"}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-15.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5318","versionConstraint":"< 0:0.9.6-15.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-5318","fix":{"state":"fixed","versions":["0:0.9.6-15.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:0.9.6-15.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5318","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5318","date":"2026-10-08","epss":0.01841,"percentile":0.78346}],"risk":0.9573200000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:18286","link":"https://access.redhat.com/errata/RHSA-2025:18286"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5318","description":"A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior."},"relatedVulnerabilities":[{"id":"CVE-2025-5318","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5318","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5318","date":"2026-10-08","epss":0.01841,"percentile":0.78346}],"urls":["https://access.redhat.com/errata/RHSA-2025:18231","https://access.redhat.com/errata/RHSA-2025:18275","https://access.redhat.com/errata/RHSA-2025:18286","https://access.redhat.com/errata/RHSA-2025:19012","https://access.redhat.com/errata/RHSA-2025:19098","https://access.redhat.com/errata/RHSA-2025:19101","https://access.redhat.com/errata/RHSA-2025:19295","https://access.redhat.com/errata/RHSA-2025:19300","https://access.redhat.com/errata/RHSA-2025:19313","https://access.redhat.com/errata/RHSA-2025:19400","https://access.redhat.com/errata/RHSA-2025:19401","https://access.redhat.com/errata/RHSA-2025:19470","https://access.redhat.com/errata/RHSA-2025:19472","https://access.redhat.com/errata/RHSA-2025:19807","https://access.redhat.com/errata/RHSA-2025:19864","https://access.redhat.com/errata/RHSA-2025:20943","https://access.redhat.com/errata/RHSA-2025:21013","https://access.redhat.com/errata/RHSA-2025:21329","https://access.redhat.com/errata/RHSA-2025:21829","https://access.redhat.com/errata/RHSA-2025:22275","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:0326","https://access.redhat.com/errata/RHSA-2026:1541","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/security/cve/CVE-2025-5318","https://bugzilla.redhat.com/show_bug.cgi?id=2369131","https://www.libssh.org/security/advisories/CVE-2025-5318.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5318","description":"A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-15.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-5318","versionConstraint":"< 0:0.9.6-15.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-5318","fix":{"state":"fixed","versions":["0:0.9.6-15.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:0.9.6-15.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5318","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5318","date":"2026-10-08","epss":0.01841,"percentile":0.78346}],"risk":0.9573200000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:18286","link":"https://access.redhat.com/errata/RHSA-2025:18286"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5318","description":"A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior."},"relatedVulnerabilities":[{"id":"CVE-2025-5318","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5318","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5318","date":"2026-10-08","epss":0.01841,"percentile":0.78346}],"urls":["https://access.redhat.com/errata/RHSA-2025:18231","https://access.redhat.com/errata/RHSA-2025:18275","https://access.redhat.com/errata/RHSA-2025:18286","https://access.redhat.com/errata/RHSA-2025:19012","https://access.redhat.com/errata/RHSA-2025:19098","https://access.redhat.com/errata/RHSA-2025:19101","https://access.redhat.com/errata/RHSA-2025:19295","https://access.redhat.com/errata/RHSA-2025:19300","https://access.redhat.com/errata/RHSA-2025:19313","https://access.redhat.com/errata/RHSA-2025:19400","https://access.redhat.com/errata/RHSA-2025:19401","https://access.redhat.com/errata/RHSA-2025:19470","https://access.redhat.com/errata/RHSA-2025:19472","https://access.redhat.com/errata/RHSA-2025:19807","https://access.redhat.com/errata/RHSA-2025:19864","https://access.redhat.com/errata/RHSA-2025:20943","https://access.redhat.com/errata/RHSA-2025:21013","https://access.redhat.com/errata/RHSA-2025:21329","https://access.redhat.com/errata/RHSA-2025:21829","https://access.redhat.com/errata/RHSA-2025:22275","https://access.redhat.com/errata/RHSA-2025:23078","https://access.redhat.com/errata/RHSA-2025:23079","https://access.redhat.com/errata/RHSA-2025:23080","https://access.redhat.com/errata/RHSA-2026:0326","https://access.redhat.com/errata/RHSA-2026:1541","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/security/cve/CVE-2025-5318","https://bugzilla.redhat.com/show_bug.cgi?id=2369131","https://www.libssh.org/security/advisories/CVE-2025-5318.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5318","description":"A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-34182","versionConstraint":">= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-34182","fix":{"state":"fixed","versions":["3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34182","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34182","date":"2026-10-08","epss":0.01057,"percentile":0.63405}],"risk":0.9565849999999999,"urls":["https://github.com/openssl/openssl/commit/03c1f4d45fb963aee7d5833390c507cd290182bc","https://github.com/openssl/openssl/commit/439ed7d2c0962ce964482727264668bf277c333f","https://github.com/openssl/openssl/commit/7947e6a81eb8776802f159fb6762cb7fcf7e34c7","https://github.com/openssl/openssl/commit/9fd97f8cfdc2c0be214998de3b2b55c8edf6c7ac","https://github.com/openssl/openssl/commit/d2ca86bcd43e4f17d899f347101766b6107676e0","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34182","description":"Issue Summary: Cryptographic Message Services (CMS) processing fails to perform\nsufficient input validation on the cipher and tag length fields of\nAuthEnvelopedData containers, leading to various potential compromises.\n\nImpact Summary: Attackers making use of these vulnerabilities may achieve\nkey-equivalent functionality for a given CMS recipient and/or bypass integrity\nvalidation for a given message.\n\nIn one use case, an attacker may send a CMS message containing\nAuthEnvelopedData with the cipher specified as a non-AEAD cipher.  OpenSSL\nerroneously allows this selection, and attempts to decrypt and validate the\nmessage.\n\nAn on-path attacker who captures one legitimate AES-GCM AuthEnvelopedData\naddressed to the victim can re-emit it with the recipientInfos set left\nbyte-for-byte intact, so the victim's private key still unwraps the genuine CEK\n(the content-encryption key), but with the inner OID rewritten to AES-256-OFB\n(Output Feedback Mode, an unauthenticated keystream mode) and with an\nattacker-chosen IV and ciphertext. The victim initializes AES-256-OFB under the\nreal CEK, never consults the MAC field, and CMS_decrypt() returns success.\n\nIf the application under attack responds to the attacker with any indicator\nshowing success or failure of the decryption effort, it is possible for the\nattacker to use this as an oracle to obtain key equivalent functionality for the\nCEK used for the chosen recipient of the message.\n\nIn another use case, an attacker can reduce the tag length of the chosen AEAD\ncipher for a given AuthEnvelopedData container to be a single byte long,\nallowing an attacker to brute force CMS decryption, producing an integrity\nbypass for applications that trust CMS_decrypt() to reject modified content.\n\nThe FIPS modules are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.10.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"risk":0.95628,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)"},"relatedVulnerabilities":[{"id":"CVE-2026-54513","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.10.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"risk":0.95628,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)"},"relatedVulnerabilities":[{"id":"CVE-2026-54513","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"1435e8d59fac6b89","cpes":["cpe:2.3:a:redhat:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.30-9.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=tar-1.30-9.el8.src.rpm","type":"rpm","version":"2:1.30-9.el8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-9923","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"tar","version":"2:1.30-9.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-9923","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9923","date":"2026-10-08","epss":0.03028,"percentile":0.87086}],"risk":0.9538199999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-9923","description":"pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers."},"relatedVulnerabilities":[{"id":"CVE-2019-9923","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-9923","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-9923","date":"2026-10-08","epss":0.03028,"percentile":0.87086}],"urls":["http://git.savannah.gnu.org/cgit/tar.git/commit/?id=cb07844454d8cc9fb21f53ace75975f91185a120","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00077.html","http://savannah.gnu.org/bugs/?55369","https://bugs.launchpad.net/ubuntu/+source/tar/+bug/1810241","https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9923","description":"pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers."}]},{"artifact":{"id":"4255208621dfded4","cpes":["cpe:2.3:a:platform-python-setuptools:platform-python-setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python-setuptools:platform_python_setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_setuptools:platform-python-setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_setuptools:platform_python_setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform-python-setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python_setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python-setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python_setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python-setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python_setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python-setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python_setuptools:39.2.0-8.el8_10:*:*:*:*:*:*:*"],"name":"platform-python-setuptools","purl":"pkg:rpm/redhat/platform-python-setuptools@39.2.0-8.el8_10?arch=noarch&distro=rhel-8.10&upstream=python-setuptools-39.2.0-8.el8_10.src.rpm","type":"rpm","version":"39.2.0-8.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-setuptools","version":"39.2.0-8.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:39.2.0-9.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-47273","versionConstraint":"< 0:39.2.0-9.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-setuptools","version":"39.2.0-8.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-47273","fix":{"state":"fixed","versions":["0:39.2.0-9.el8_10"],"available":[{"date":"2025-07-16","kind":"first-observed","version":"0:39.2.0-9.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"risk":0.9310949999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:11036","link":"https://access.redhat.com/errata/RHSA-2025:11036"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-47273","description":"A path traversal vulnerability in the Python setuptools library allows attackers with limited system access to write files outside the intended temporary directory by manipulating package download URLs. This flaw bypasses basic filename sanitization and can lead to unauthorized overwrites of important system files, creating opportunities for further compromise. While it doesn't expose data or require user interaction, it poses a high integrity risk and is especially concerning in environments that rely on automated package handling or internal tooling built on setuptools."},"relatedVulnerabilities":[{"id":"CVE-2025-47273","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"urls":["https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88","https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b","https://github.com/pypa/setuptools/issues/4946","https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf","https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue."}]},{"artifact":{"id":"b55669e476992d37","cpes":["cpe:2.3:a:python3-setuptools-wheel:python3-setuptools-wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools-wheel:python3_setuptools_wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_wheel:python3-setuptools-wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_wheel:python3_setuptools_wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3-setuptools-wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3_setuptools_wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3-setuptools-wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3_setuptools_wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-setuptools-wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_setuptools_wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-setuptools-wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_setuptools_wheel:39.2.0-8.el8_10:*:*:*:*:*:*:*"],"name":"python3-setuptools-wheel","purl":"pkg:rpm/redhat/python3-setuptools-wheel@39.2.0-8.el8_10?arch=noarch&distro=rhel-8.10&upstream=python-setuptools-39.2.0-8.el8_10.src.rpm","type":"rpm","version":"39.2.0-8.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-setuptools","version":"39.2.0-8.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:39.2.0-9.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-47273","versionConstraint":"< 0:39.2.0-9.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-setuptools","version":"39.2.0-8.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-47273","fix":{"state":"fixed","versions":["0:39.2.0-9.el8_10"],"available":[{"date":"2025-07-16","kind":"first-observed","version":"0:39.2.0-9.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"risk":0.9310949999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:11036","link":"https://access.redhat.com/errata/RHSA-2025:11036"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-47273","description":"A path traversal vulnerability in the Python setuptools library allows attackers with limited system access to write files outside the intended temporary directory by manipulating package download URLs. This flaw bypasses basic filename sanitization and can lead to unauthorized overwrites of important system files, creating opportunities for further compromise. While it doesn't expose data or require user interaction, it poses a high integrity risk and is especially concerning in environments that rely on automated package handling or internal tooling built on setuptools."},"relatedVulnerabilities":[{"id":"CVE-2025-47273","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"urls":["https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88","https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b","https://github.com/pypa/setuptools/issues/4946","https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf","https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-47273","versionConstraint":"< 0:3.9.20-2.module+el8.10.0+23441+1124c1da (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-47273","fix":{"state":"fixed","versions":["0:3.9.20-2.module+el8.10.0+23441+1124c1da"],"available":[{"date":"2025-09-01","kind":"first-observed","version":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"risk":0.9310949999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14900","link":"https://access.redhat.com/errata/RHSA-2025:14900"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-47273","description":"A path traversal vulnerability in the Python setuptools library allows attackers with limited system access to write files outside the intended temporary directory by manipulating package download URLs. This flaw bypasses basic filename sanitization and can lead to unauthorized overwrites of important system files, creating opportunities for further compromise. While it doesn't expose data or require user interaction, it poses a high integrity risk and is especially concerning in environments that rely on automated package handling or internal tooling built on setuptools."},"relatedVulnerabilities":[{"id":"CVE-2025-47273","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"urls":["https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88","https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b","https://github.com/pypa/setuptools/issues/4946","https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf","https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-47273","versionConstraint":"< 0:3.9.20-2.module+el8.10.0+23441+1124c1da (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-47273","fix":{"state":"fixed","versions":["0:3.9.20-2.module+el8.10.0+23441+1124c1da"],"available":[{"date":"2025-09-01","kind":"first-observed","version":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"risk":0.9310949999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14900","link":"https://access.redhat.com/errata/RHSA-2025:14900"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-47273","description":"A path traversal vulnerability in the Python setuptools library allows attackers with limited system access to write files outside the intended temporary directory by manipulating package download URLs. This flaw bypasses basic filename sanitization and can lead to unauthorized overwrites of important system files, creating opportunities for further compromise. While it doesn't expose data or require user interaction, it poses a high integrity risk and is especially concerning in environments that rely on automated package handling or internal tooling built on setuptools."},"relatedVulnerabilities":[{"id":"CVE-2025-47273","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47273","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-47273","date":"2026-10-08","epss":0.01539,"percentile":0.74138}],"urls":["https://github.com/pypa/setuptools/blob/6ead555c5fb29bc57fe6105b1bffc163f56fd558/setuptools/package_index.py#L810C1-L825C88","https://github.com/pypa/setuptools/commit/250a6d17978f9f6ac3ac887091f2d32886fbbb0b","https://github.com/pypa/setuptools/issues/4946","https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf","https://lists.debian.org/debian-lts-announce/2025/05/msg00035.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-74.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-0938","versionConstraint":"< 0:3.6.8-74.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-0938","fix":{"state":"fixed","versions":["0:3.6.8-74.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-74.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"risk":0.9180399999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:5588","link":"https://access.redhat.com/errata/RHSA-2026:5588"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-0938","description":"A flaw was found in Python. The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accept domain names that included square brackets, which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."},"relatedVulnerabilities":[{"id":"CVE-2025-0938","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"urls":["https://github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba","https://github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403","https://github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568","https://github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab","https://github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a","https://github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32","https://github.com/python/cpython/issues/105704","https://github.com/python/cpython/pull/129418","https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html","https://security.netapp.com/advisory/ntap-20250314-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0938","description":"The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-74.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-0938","versionConstraint":"< 0:3.6.8-74.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-0938","fix":{"state":"fixed","versions":["0:3.6.8-74.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-74.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"risk":0.9180399999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:5588","link":"https://access.redhat.com/errata/RHSA-2026:5588"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-0938","description":"A flaw was found in Python. The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accept domain names that included square brackets, which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."},"relatedVulnerabilities":[{"id":"CVE-2025-0938","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"urls":["https://github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba","https://github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403","https://github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568","https://github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab","https://github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a","https://github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32","https://github.com/python/cpython/issues/105704","https://github.com/python/cpython/pull/129418","https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html","https://security.netapp.com/advisory/ntap-20250314-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0938","description":"The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-0938","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-0938","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"risk":0.9180399999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-0938","description":"A flaw was found in Python. The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accept domain names that included square brackets, which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."},"relatedVulnerabilities":[{"id":"CVE-2025-0938","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"urls":["https://github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba","https://github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403","https://github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568","https://github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab","https://github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a","https://github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32","https://github.com/python/cpython/issues/105704","https://github.com/python/cpython/pull/129418","https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html","https://security.netapp.com/advisory/ntap-20250314-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0938","description":"The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-0938","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-0938","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"risk":0.9180399999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-0938","description":"A flaw was found in Python. The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accept domain names that included square brackets, which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."},"relatedVulnerabilities":[{"id":"CVE-2025-0938","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-0938","cwe":"CWE-20","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-0938","date":"2026-10-08","epss":0.01556,"percentile":0.74418}],"urls":["https://github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba","https://github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403","https://github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568","https://github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab","https://github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a","https://github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32","https://github.com/python/cpython/issues/105704","https://github.com/python/cpython/pull/129418","https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB/","https://lists.debian.org/debian-lts-announce/2025/03/msg00013.html","https://security.netapp.com/advisory/ntap-20250314-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-0938","description":"The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7592","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-7592","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"risk":0.89817,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7592","description":"A flaw was found in the `http.cookies` module in the Python package. When parsing cookies that contain backslashes, under certain circumstances, the module uses an algorithm with quadratic complexity, leading to excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2024-7592","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"urls":["https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621","https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef","https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06","https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a","https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f","https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774","https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1","https://github.com/python/cpython/issues/123067","https://github.com/python/cpython/pull/123075","https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20241018-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7592","description":"There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7592","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-7592","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"risk":0.89817,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7592","description":"A flaw was found in the `http.cookies` module in the Python package. When parsing cookies that contain backslashes, under certain circumstances, the module uses an algorithm with quadratic complexity, leading to excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2024-7592","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"urls":["https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621","https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef","https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06","https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a","https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f","https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774","https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1","https://github.com/python/cpython/issues/123067","https://github.com/python/cpython/pull/123075","https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20241018-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7592","description":"There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-7592","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-7592","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"risk":0.89817,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7592","description":"A flaw was found in the `http.cookies` module in the Python package. When parsing cookies that contain backslashes, under certain circumstances, the module uses an algorithm with quadratic complexity, leading to excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2024-7592","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"urls":["https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621","https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef","https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06","https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a","https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f","https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774","https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1","https://github.com/python/cpython/issues/123067","https://github.com/python/cpython/pull/123075","https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20241018-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7592","description":"There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-7592","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-7592","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"risk":0.89817,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-7592","description":"A flaw was found in the `http.cookies` module in the Python package. When parsing cookies that contain backslashes, under certain circumstances, the module uses an algorithm with quadratic complexity, leading to excessive CPU consumption."},"relatedVulnerabilities":[{"id":"CVE-2024-7592","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7592","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-7592","cwe":"CWE-1333","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-7592","date":"2026-10-08","epss":0.02303,"percentile":0.82804}],"urls":["https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621","https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef","https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06","https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a","https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f","https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774","https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1","https://github.com/python/cpython/issues/123067","https://github.com/python/cpython/pull/123075","https://mail.python.org/archives/list/security-announce@python.org/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20241018-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7592","description":"There is a LOW severity vulnerability affecting CPython, specifically the\n'http.cookies' standard library module.\n\n\nWhen parsing cookies that contained backslashes for quoted characters in\nthe cookie value, the parser would use an algorithm with quadratic\ncomplexity, resulting in excess CPU resources being used while parsing the\nvalue."}]},{"artifact":{"id":"15ab448eaed3b129","cpes":["cpe:2.3:a:libarchive:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.3.3-5.el8?arch=x86_64&distro=rhel-8.10&upstream=libarchive-3.3.3-5.el8.src.rpm","type":"rpm","version":"3.3.3-5.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.3.3-7.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5121","versionConstraint":"< 0:3.3.3-7.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libarchive","version":"0:3.3.3-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5121","fix":{"state":"fixed","versions":["0:3.3.3-7.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.3.3-7.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5121","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-5121","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-5121","date":"2026-10-08","epss":0.0143,"percentile":0.72215}],"risk":0.89375,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:8534","link":"https://access.redhat.com/errata/RHSA-2026:8534"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5121","description":"A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-5121","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5121","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-5121","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-5121","date":"2026-10-08","epss":0.0143,"percentile":0.72215}],"urls":["https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10097","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:12071","https://access.redhat.com/errata/RHSA-2026:12274","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14773","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:15087","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:17596","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:20040","https://access.redhat.com/errata/RHSA-2026:21690","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:8510","https://access.redhat.com/errata/RHSA-2026:8517","https://access.redhat.com/errata/RHSA-2026:8521","https://access.redhat.com/errata/RHSA-2026:8534","https://access.redhat.com/errata/RHSA-2026:8864","https://access.redhat.com/errata/RHSA-2026:8866","https://access.redhat.com/errata/RHSA-2026:8867","https://access.redhat.com/errata/RHSA-2026:8873","https://access.redhat.com/errata/RHSA-2026:8908","https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/errata/RHSA-2026:9026","https://access.redhat.com/errata/RHSA-2026:9592","https://access.redhat.com/errata/RHSA-2026:9832","https://access.redhat.com/security/cve/CVE-2026-5121","https://bugzilla.redhat.com/show_bug.cgi?id=2452945","https://github.com/advisories/GHSA-2vwv-vqpv-v8vc","https://github.com/libarchive/libarchive/pull/2934","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5121","description":"A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system."}]},{"artifact":{"id":"fa819346ba1b9bc6","cpes":["cpe:2.3:a:systemd:systemd:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:rpm/redhat/systemd@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-3997","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"0:239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-3997","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-08","epss":0.01694,"percentile":0.76418}],"risk":0.8893500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."},"relatedVulnerabilities":[{"id":"CVE-2021-3997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-08","epss":0.01694,"percentile":0.76418}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3997","https://bugzilla.redhat.com/show_bug.cgi?id=2024639","https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1","https://security.gentoo.org/glsa/202305-15","https://www.openwall.com/lists/oss-security/2022/01/10/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."}]},{"artifact":{"id":"35ec2c60a4c27ac2","cpes":["cpe:2.3:a:systemd-libs:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd-libs:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd-libs","purl":"pkg:rpm/redhat/systemd-libs@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"239-82.el8_10.5"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3997","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-3997","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-08","epss":0.01694,"percentile":0.76418}],"risk":0.8893500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."},"relatedVulnerabilities":[{"id":"CVE-2021-3997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-08","epss":0.01694,"percentile":0.76418}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3997","https://bugzilla.redhat.com/show_bug.cgi?id=2024639","https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1","https://security.gentoo.org/glsa/202305-15","https://www.openwall.com/lists/oss-security/2022/01/10/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."}]},{"artifact":{"id":"3072771f0e906f1d","cpes":["cpe:2.3:a:systemd-pam:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd-pam:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd-pam","purl":"pkg:rpm/redhat/systemd-pam@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"239-82.el8_10.5"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2021-3997","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-3997","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-08","epss":0.01694,"percentile":0.76418}],"risk":0.8893500000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."},"relatedVulnerabilities":[{"id":"CVE-2021-3997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-3997","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-3997","date":"2026-10-08","epss":0.01694,"percentile":0.76418}],"urls":["https://access.redhat.com/security/cve/CVE-2021-3997","https://bugzilla.redhat.com/show_bug.cgi?id=2024639","https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1","https://security.gentoo.org/glsa/202305-15","https://www.openwall.com/lists/oss-security/2022/01/10/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-3997","description":"A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19186","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19186","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19186","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19186","date":"2026-10-08","epss":0.01838,"percentile":0.7832}],"risk":0.87305,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19186","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a buffer over-read, resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2020-19186","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19186","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19186","date":"2026-10-08","epss":0.01838,"percentile":0.7832}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc2.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19186","description":"Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19186","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19186","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19186","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19186","date":"2026-10-08","epss":0.01838,"percentile":0.7832}],"risk":0.87305,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19186","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a buffer over-read, resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2020-19186","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19186","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19186","date":"2026-10-08","epss":0.01838,"percentile":0.7832}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc2.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19186","description":"Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-21.el8_10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-6021","versionConstraint":"< 0:2.9.7-21.el8_10.1 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6021","fix":{"state":"fixed","versions":["0:2.9.7-21.el8_10.1"],"available":[{"date":"2025-07-10","kind":"first-observed","version":"0:2.9.7-21.el8_10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6021","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2025-6021","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-6021","date":"2026-10-08","epss":0.01367,"percentile":0.71018}],"risk":0.8543749999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10698","link":"https://access.redhat.com/errata/RHSA-2025:10698"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6021","description":"A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input."},"relatedVulnerabilities":[{"id":"CVE-2025-6021","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6021","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2025-6021","cwe":"CWE-787","type":"Secondary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-6021","date":"2026-10-08","epss":0.01367,"percentile":0.71018}],"urls":["https://access.redhat.com/errata/RHSA-2025:10630","https://access.redhat.com/errata/RHSA-2025:10698","https://access.redhat.com/errata/RHSA-2025:10699","https://access.redhat.com/errata/RHSA-2025:11580","https://access.redhat.com/errata/RHSA-2025:11673","https://access.redhat.com/errata/RHSA-2025:12098","https://access.redhat.com/errata/RHSA-2025:12099","https://access.redhat.com/errata/RHSA-2025:12199","https://access.redhat.com/errata/RHSA-2025:12237","https://access.redhat.com/errata/RHSA-2025:12239","https://access.redhat.com/errata/RHSA-2025:12240","https://access.redhat.com/errata/RHSA-2025:12241","https://access.redhat.com/errata/RHSA-2025:13267","https://access.redhat.com/errata/RHSA-2025:13289","https://access.redhat.com/errata/RHSA-2025:13325","https://access.redhat.com/errata/RHSA-2025:13335","https://access.redhat.com/errata/RHSA-2025:13336","https://access.redhat.com/errata/RHSA-2025:14059","https://access.redhat.com/errata/RHSA-2025:14396","https://access.redhat.com/errata/RHSA-2025:15308","https://access.redhat.com/errata/RHSA-2025:15672","https://access.redhat.com/errata/RHSA-2025:19020","https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2025-6021","https://bugzilla.redhat.com/show_bug.cgi?id=2372406","https://gitlab.gnome.org/GNOME/libxml2/-/issues/926","https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6021","description":"A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42009","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42009","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42009","date":"2026-10-08","epss":0.01129,"percentile":0.65367}],"risk":0.8467499999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42009","description":"A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-42009","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42009","cwe":"CWE-475","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42009","date":"2026-10-08","epss":0.01129,"percentile":0.65367}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:29794","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42009","https://bugzilla.redhat.com/show_bug.cgi?id=2467279","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-2","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42009.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42009","description":"A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33846","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-33846","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33846","date":"2026-10-08","epss":0.01123,"percentile":0.65216}],"risk":0.8422499999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-33846","description":"A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-33846","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33846","cwe":"CWE-130","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33846","date":"2026-10-08","epss":0.01123,"percentile":0.65216}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33846","https://bugzilla.redhat.com/show_bug.cgi?id=2450625","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33846.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33846","description":"A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption."}]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-1.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-59375","versionConstraint":"< 0:2.5.0-1.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-59375","fix":{"state":"fixed","versions":["0:2.5.0-1.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.5.0-1.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-59375","date":"2026-10-08","epss":0.01315,"percentile":0.69879}],"risk":0.8416,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:21776","link":"https://access.redhat.com/errata/RHSA-2025:21776"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-59375","description":"A memory amplification vulnerability in libexpat allows attackers to trigger excessive dynamic memory allocations by submitting specially crafted XML input. A small input (~250 KiB) can cause the parser to allocate hundreds of megabytes, leading to denial-of-service (DoS) through memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2025-59375","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59375","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-59375","date":"2026-10-08","epss":0.01315,"percentile":0.69879}],"urls":["https://github.com/libexpat/libexpat/blob/676a4c531ec768732fac215da9730b5f50fbd2bf/expat/Changes#L45-L74","https://github.com/libexpat/libexpat/blob/R_2_7_2/expat/Changes","https://github.com/libexpat/libexpat/issues/1018","https://github.com/libexpat/libexpat/pull/1034","https://issues.oss-fuzz.com/issues/439133977","http://www.openwall.com/lists/oss-security/2025/09/16/2","http://www.openwall.com/lists/oss-security/2026/05/01/5","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59375","description":"libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-0466","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-0466","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0466","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-0466","date":"2026-10-08","epss":0.01625,"percentile":0.75423}],"risk":0.8368750000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-0466","description":"A flaw was found in OpenSSL. The X509_VERIFY_PARAM_add0_policy() function is documented to enable the certificate policy check when doing certificate verification implicitly. However, implementing the function does not enable the check, allowing certificates with invalid or incorrect policies to pass the certificate verification. Suddenly enabling the policy check could break existing deployments, so it was decided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy() function. The applications that require OpenSSL to perform certificate policy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly enable the policy check by calling X509_VERIFY_PARAM_set_flags() with the X509_V_FLAG_POLICY_CHECK flag argument. Certificate policy checks are disabled by default in OpenSSL and are not commonly used by applications."},"relatedVulnerabilities":[{"id":"CVE-2023-0466","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0466","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-0466","date":"2026-10-08","epss":0.01625,"percentile":0.75423}],"urls":["http://www.openwall.com/lists/oss-security/2023/09/28/4","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0d16b7e99aafc0b4a6d729eec65a411a7e025f0a","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=51e8a84ce742db0f6c70510d0159dad8f7825908","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=73398dea26de9899fb4baa94098ad0a61f435c72","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fc814a30fc4f0bc54fcea7d9a7462f5457aab061","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230414-0001/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230328.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0466","description":"The function X509_VERIFY_PARAM_add0_policy() is documented to\nimplicitly enable the certificate policy check when doing certificate\nverification. However the implementation of the function does not\nenable the check which allows certificates with invalid or incorrect\npolicies to pass the certificate verification.\n\nAs suddenly enabling the policy check could break existing deployments it was\ndecided to keep the existing behavior of the X509_VERIFY_PARAM_add0_policy()\nfunction.\n\nInstead the applications that require OpenSSL to perform certificate\npolicy check need to use X509_VERIFY_PARAM_set1_policies() or explicitly\nenable the policy check by calling X509_VERIFY_PARAM_set_flags() with\nthe X509_V_FLAG_POLICY_CHECK flag argument.\n\nCertificate policy checks are disabled by default in OpenSSL and are not\ncommonly used by applications."}]},{"artifact":{"id":"28726da5e507706a","cpes":["cpe:2.3:a:nmap-ncat:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap-ncat:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap_ncat:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap_ncat:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*"],"name":"nmap-ncat","purl":"pkg:rpm/redhat/nmap-ncat@7.92-1.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=nmap-7.92-1.el8.src.rpm","type":"rpm","version":"2:7.92-1.el8","language":"","licenses":["Nmap"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nmap","version":"7.92-1.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58058","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"nmap","version":"7.92-1.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58058","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58058","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58058","date":"2026-10-08","epss":0.01454,"percentile":0.7266}],"risk":0.83605,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58058","description":"A flaw was found in Nmap. A remote attacker or a scanned target can send a specially crafted IPv6 response with a truncated extension header. This can lead to an integer underflow, causing out-of-bounds reads and a denial of service (DoS) due to a crash during raw IPv6 scans."},"relatedVulnerabilities":[{"id":"CVE-2026-58058","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58058","cwe":"CWE-191","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58058","date":"2026-10-08","epss":0.01454,"percentile":0.7266}],"urls":["https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc","https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83","https://nmap.org/changelog.html","https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58058","description":"Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19187","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19187","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19187","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19187","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19187","description":"A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2020-19187","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19187","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19187","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc3.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19187","description":"Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19188","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19188","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19188","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19188","description":"A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a stack-based buffer overflow, resulting in an application crash, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2020-19188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19188","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19188","description":"Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19190","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19190","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19190","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19190","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2020-19190","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19190","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19190","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc6.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19190","description":"Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19187","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19187","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19187","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19187","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19187","description":"A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2020-19187","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19187","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19187","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc3.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19187","description":"Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19188","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19188","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19188","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19188","description":"A flaw was found in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a stack-based buffer overflow, resulting in an application crash, leading to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2020-19188","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19188","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19188","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc4.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19188","description":"Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19190","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19190","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19190","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19190","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19190","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash."},"relatedVulnerabilities":[{"id":"CVE-2020-19190","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19190","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19190","date":"2026-10-08","epss":0.01753,"percentile":0.77216}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc6.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19190","description":"Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19185","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19185","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19185","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19185","date":"2026-10-08","epss":0.01753,"percentile":0.77215}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19185","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, causing denial of service."},"relatedVulnerabilities":[{"id":"CVE-2020-19185","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19185","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19185","date":"2026-10-08","epss":0.01753,"percentile":0.77215}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc1.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19185","description":"Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-19185","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2020-19185","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19185","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19185","date":"2026-10-08","epss":0.01753,"percentile":0.77215}],"risk":0.8326749999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2020-19185","description":"A flaw has been identified in the ncurses library. This issue occurs when processing a crafted terminfo database, causing a heap-based buffer overflow, resulting in an application crash, causing denial of service."},"relatedVulnerabilities":[{"id":"CVE-2020-19185","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-19185","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-19185","date":"2026-10-08","epss":0.01753,"percentile":0.77215}],"urls":["http://seclists.org/fulldisclosure/2023/Dec/10","http://seclists.org/fulldisclosure/2023/Dec/11","http://seclists.org/fulldisclosure/2023/Dec/9","https://github.com/zjuchenyuan/fuzzpoc/blob/master/infotocap_poc1.md","https://security.netapp.com/advisory/ntap-20231006-0005/","https://support.apple.com/kb/HT214036","https://support.apple.com/kb/HT214037","https://support.apple.com/kb/HT214038"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-19185","description":"Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-4209","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-4209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4209","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-4209","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-4209","date":"2026-10-08","epss":0.01748,"percentile":0.77139}],"risk":0.8302999999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-4209","description":"A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances."},"relatedVulnerabilities":[{"id":"CVE-2021-4209","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-4209","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-4209","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-4209","date":"2026-10-08","epss":0.01748,"percentile":0.77139}],"urls":["https://access.redhat.com/security/cve/CVE-2021-4209","https://bugzilla.redhat.com/show_bug.cgi?id=2044156","https://gitlab.com/gnutls/gnutls/-/commit/3db352734472d851318944db13be73da61300568","https://gitlab.com/gnutls/gnutls/-/issues/1306","https://gitlab.com/gnutls/gnutls/-/merge_requests/1503","https://security.netapp.com/advisory/ntap-20220915-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-4209","description":"A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:1.1.1k-14.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9230","versionConstraint":"< 1:1.1.1k-14.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-9230","fix":{"state":"fixed","versions":["1:1.1.1k-14.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"1:1.1.1k-14.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9230","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-9230","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9230","date":"2026-10-08","epss":0.01554,"percentile":0.74399}],"risk":0.8236200000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:0337","link":"https://access.redhat.com/errata/RHSA-2026:0337"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-9230","description":"A flaw was found in the OpenSSL CMS implementation (RFC 3211 KEK Unwrap). This vulnerability allows memory corruption, an application level denial of service, or potential execution of attacker-supplied code via crafted CMS messages using password-based encryption (PWRI)."},"relatedVulnerabilities":[{"id":"CVE-2025-9230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9230","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2025-9230","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-9230","date":"2026-10-08","epss":0.01554,"percentile":0.74399}],"urls":["https://github.com/openssl/openssl/commit/5965ea5dd6960f36d8b7f74f8eac67a8eb8f2b45","https://github.com/openssl/openssl/commit/9e91358f365dee6c446dcdcdb01c04d2743fd280","https://github.com/openssl/openssl/commit/a79c4ce559c6a3a8fd4109e9f33c1185d5bf2def","https://github.com/openssl/openssl/commit/b5282d677551afda7d20e9c00e09561b547b2dfd","https://github.com/openssl/openssl/commit/bae259a211ada6315dc50900686daaaaaa55f482","https://github.openssl.org/openssl/extended-releases/commit/c2b96348bfa662f25f4fabf81958ae822063dae3","https://github.openssl.org/openssl/extended-releases/commit/dfbaf161d8dafc1132dd88cd48ad990ed9b4c8ba","https://openssl-library.org/news/secadv/20250930.txt","http://www.openwall.com/lists/oss-security/2025/09/30/5","https://lists.debian.org/debian-lts-announce/2025/10/msg00001.html","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9230","description":"Issue summary: An application trying to decrypt CMS messages encrypted using\npassword based encryption can trigger an out-of-bounds read and write.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application. The out-of-bounds write can cause\na memory corruption which can have various consequences including\na Denial of Service or Execution of attacker-supplied code.\n\nAlthough the consequences of a successful exploit of this vulnerability\ncould be severe, the probability that the attacker would be able to\nperform it is low. Besides, password based (PWRI) encryption support in CMS\nmessages is very rarely used. For that reason the issue was assessed as\nModerate severity according to our Security Policy.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"15ab448eaed3b129","cpes":["cpe:2.3:a:libarchive:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.3.3-5.el8?arch=x86_64&distro=rhel-8.10&upstream=libarchive-3.3.3-5.el8.src.rpm","type":"rpm","version":"3.3.3-5.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.3.3-7.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4424","versionConstraint":"< 0:3.3.3-7.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libarchive","version":"0:3.3.3-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4424","fix":{"state":"fixed","versions":["0:3.3.3-7.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.3.3-7.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4424","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4424","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4424","date":"2026-10-08","epss":0.01073,"percentile":0.63877}],"risk":0.8047499999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:8534","link":"https://access.redhat.com/errata/RHSA-2026:8534"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4424","description":"A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction."},"relatedVulnerabilities":[{"id":"CVE-2026-4424","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4424","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4424","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4424","date":"2026-10-08","epss":0.01073,"percentile":0.63877}],"urls":["https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10097","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:12071","https://access.redhat.com/errata/RHSA-2026:12274","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14773","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:15087","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:17596","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:20040","https://access.redhat.com/errata/RHSA-2026:21690","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:8492","https://access.redhat.com/errata/RHSA-2026:8510","https://access.redhat.com/errata/RHSA-2026:8517","https://access.redhat.com/errata/RHSA-2026:8521","https://access.redhat.com/errata/RHSA-2026:8534","https://access.redhat.com/errata/RHSA-2026:8864","https://access.redhat.com/errata/RHSA-2026:8865","https://access.redhat.com/errata/RHSA-2026:8866","https://access.redhat.com/errata/RHSA-2026:8867","https://access.redhat.com/errata/RHSA-2026:8873","https://access.redhat.com/errata/RHSA-2026:8908","https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/errata/RHSA-2026:9026","https://access.redhat.com/errata/RHSA-2026:9592","https://access.redhat.com/errata/RHSA-2026:9832","https://access.redhat.com/security/cve/CVE-2026-4424","https://bugzilla.redhat.com/show_bug.cgi?id=2449006","https://github.com/libarchive/libarchive/pull/2898","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4424.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4424","description":"A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory information without requiring authentication or user interaction."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-32988","versionConstraint":"< 0:3.6.16-8.el8_10.4 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-32988","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.4"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.16-8.el8_10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32988","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32988","date":"2026-10-08","epss":0.01373,"percentile":0.71137}],"risk":0.7894749999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:17415","link":"https://access.redhat.com/errata/RHSA-2025:17415"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-32988","description":"A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.\nThis vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior."},"relatedVulnerabilities":[{"id":"CVE-2025-32988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32988","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32988","date":"2026-10-08","epss":0.01373,"percentile":0.71137}],"urls":["https://access.redhat.com/errata/RHSA-2025:16115","https://access.redhat.com/errata/RHSA-2025:16116","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:17348","https://access.redhat.com/errata/RHSA-2025:17361","https://access.redhat.com/errata/RHSA-2025:17415","https://access.redhat.com/errata/RHSA-2025:19088","https://access.redhat.com/errata/RHSA-2025:22529","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/security/cve/CVE-2025-32988","https://bugzilla.redhat.com/show_bug.cgi?id=2359622","https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html","http://www.openwall.com/lists/oss-security/2025/07/11/3","https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32988","description":"A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when the parent function or caller later attempts to free the same structure.\n\nThis vulnerability can be triggered using only public GnuTLS APIs and may result in denial of service or memory corruption, depending on allocator behavior."}]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.10.0,<=2.18.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"risk":0.7792200000000001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation"},"relatedVulnerabilities":[{"id":"CVE-2026-54512","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.10.0,<=2.18.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"risk":0.7792200000000001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation"},"relatedVulnerabilities":[{"id":"CVE-2026-54512","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.20"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-31790","versionConstraint":">= 3.0.0, < 3.0.20||>= 3.3.0, < 3.3.7||>= 3.4.0, < 3.4.5||>= 3.5.0, < 3.5.6||>= 3.6.0, < 3.6.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-31790","fix":{"state":"fixed","versions":["3.0.20","3.3.7","3.4.5","3.5.6","3.6.2"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"3.0.20"},{"date":"2026-04-09","kind":"first-observed","version":"3.3.7"},{"date":"2026-04-09","kind":"first-observed","version":"3.4.5"},{"date":"2026-04-09","kind":"first-observed","version":"3.5.6"},{"date":"2026-04-09","kind":"first-observed","version":"3.6.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31790","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31790","date":"2026-10-08","epss":0.0103,"percentile":0.62639}],"risk":0.7725,"urls":["https://github.com/openssl/openssl/commit/001e01db3e996e13ffc72386fe79d03a6683b5ac","https://github.com/openssl/openssl/commit/abd8b2eec7e3f3fda60ecfb68498b246b52af482","https://github.com/openssl/openssl/commit/b922e24e5b23ffb9cb9e14cadff23d91e9f7e406","https://github.com/openssl/openssl/commit/d5f8e71cd0a54e961d0c3b174348f8308486f790","https://github.com/openssl/openssl/commit/eed200f58cd8645ed77e46b7e9f764e284df379e","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31790","description":"Issue summary: Applications using RSASVE key encapsulation to establish\na secret encryption key can send contents of an uninitialized memory buffer to\na malicious peer.\n\nImpact summary: The uninitialized buffer might contain sensitive data from the\nprevious execution of the application process which leads to sensitive data\nleakage to an attacker.\n\nRSA_public_encrypt() returns the number of bytes written on success and -1\non error. The affected code tests only whether the return value is non-zero.\nAs a result, if RSA encryption fails, encapsulation can still return success to\nthe caller, set the output lengths, and leave the caller to use the contents of\nthe ciphertext buffer as if a valid KEM ciphertext had been produced.\n\nIf applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an\nattacker-supplied invalid RSA public key without first validating that key,\nthen this may cause stale or uninitialized contents of the caller-provided\nciphertext buffer to be disclosed to the attacker in place of the KEM\nciphertext.\n\nAs a workaround calling EVP_PKEY_public_check() or\nEVP_PKEY_public_check_quick() before EVP_PKEY_encapsulate() will mitigate\nthe issue.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.1 and 3.0 are affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"f3dbf2601d631118","cpes":["cpe:2.3:a:python3-rpm:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-rpm:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_rpm:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_rpm:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"python3-rpm","purl":"pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.14.3-32.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-84837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"risk":0.76736,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."},"relatedVulnerabilities":[{"id":"CVE-2026-84837","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"urls":["https://access.redhat.com/security/cve/CVE-2026-84837","https://bugzilla.redhat.com/show_bug.cgi?id=2478408"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."}]},{"artifact":{"id":"6c723629f01508b1","cpes":["cpe:2.3:a:redhat:rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"0:4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-84837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"risk":0.76736,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."},"relatedVulnerabilities":[{"id":"CVE-2026-84837","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"urls":["https://access.redhat.com/security/cve/CVE-2026-84837","https://bugzilla.redhat.com/show_bug.cgi?id=2478408"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."}]},{"artifact":{"id":"e44a5dd2f875a462","cpes":["cpe:2.3:a:rpm-build-libs:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build-libs:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build_libs:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build_libs:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"rpm-build-libs","purl":"pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.14.3-32.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-84837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"risk":0.76736,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."},"relatedVulnerabilities":[{"id":"CVE-2026-84837","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"urls":["https://access.redhat.com/security/cve/CVE-2026-84837","https://bugzilla.redhat.com/show_bug.cgi?id=2478408"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."}]},{"artifact":{"id":"9c24e9e6f2be9987","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.14.3-32.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84837","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-84837","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"risk":0.76736,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."},"relatedVulnerabilities":[{"id":"CVE-2026-84837","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84837","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-84837","date":"2026-10-08","epss":0.01199,"percentile":0.67231}],"urls":["https://access.redhat.com/security/cve/CVE-2026-84837","https://bugzilla.redhat.com/show_bug.cgi?id=2478408"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84837","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-21.el8_10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-34459","versionConstraint":"< 0:2.9.7-21.el8_10.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-34459","fix":{"state":"fixed","versions":["0:2.9.7-21.el8_10.5"],"available":[{"date":"2026-06-17","kind":"first-observed","version":"0:2.9.7-21.el8_10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34459","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34459","date":"2026-10-08","epss":0.018,"percentile":0.77839}],"risk":0.765,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:26354","link":"https://access.redhat.com/errata/RHSA-2026:26354"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-34459","description":"A flaw was found in the xmllint program distributed by the libxml2 package. A buffer over-read in the xmlHTMLPrintFileContext function in the xmllint.c file may be triggered when a crafted file is processed with the xmllint program using the `--htmlout` command line option, causing an application crash and resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2024-34459","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34459","cwe":"CWE-122","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34459","date":"2026-10-08","epss":0.018,"percentile":0.77839}],"urls":["https://gitlab.gnome.org/GNOME/libxml2/-/issues/720","https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8","https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/","https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34459","description":"An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-166.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-52533","versionConstraint":"< 0:2.56.4-166.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-52533","fix":{"state":"fixed","versions":["0:2.56.4-166.el8_10"],"available":[{"date":"2025-07-17","kind":"first-observed","version":"0:2.56.4-166.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52533","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-52533","date":"2026-10-08","epss":0.01254,"percentile":0.68585}],"risk":0.7524000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:11327","link":"https://access.redhat.com/errata/RHSA-2025:11327"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-52533","description":"A flaw was found in the Glib library. A buffer overflow condition can be triggered in certain conditions due to an off-by-one error in SOCKS4_CONN_MSG_LEN. This issue may lead to an application crash or other undefined behavior."},"relatedVulnerabilities":[{"id":"CVE-2024-52533","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52533","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-52533","date":"2026-10-08","epss":0.01254,"percentile":0.68585}],"urls":["https://gitlab.gnome.org/GNOME/glib/-/issues/3461","https://gitlab.gnome.org/GNOME/glib/-/releases/2.82.1","https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home","http://www.openwall.com/lists/oss-security/2024/11/12/11","https://lists.debian.org/debian-lts-announce/2024/11/msg00020.html","https://security.netapp.com/advisory/ntap-20241206-0009/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52533","description":"gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\\0' character."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-170.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58016","versionConstraint":"< 0:2.56.4-170.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58016","fix":{"state":"fixed","versions":["0:2.56.4-170.el8_10"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"0:2.56.4-170.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"risk":0.7447499999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42090","link":"https://access.redhat.com/errata/RHSA-2026:42090"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58016","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58016","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58016","date":"2026-10-08","epss":0.00993,"percentile":0.61445}],"urls":["https://access.redhat.com/errata/RHSA-2026:42063","https://access.redhat.com/errata/RHSA-2026:42089","https://access.redhat.com/errata/RHSA-2026:42090","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:51175","https://access.redhat.com/errata/RHSA-2026:51176","https://access.redhat.com/errata/RHSA-2026:51177","https://access.redhat.com/errata/RHSA-2026:51181","https://access.redhat.com/errata/RHSA-2026:51182","https://access.redhat.com/errata/RHSA-2026:51183","https://access.redhat.com/errata/RHSA-2026:51184","https://access.redhat.com/errata/RHSA-2026:51185","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-58016","https://bugzilla.redhat.com/show_bug.cgi?id=2492257","https://gitlab.gnome.org/GNOME/glib/-/issues/3932"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016","description":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.20"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-28387","versionConstraint":">= 1.1.1, < 1.1.1zg||>= 3.0.0, < 3.0.20||>= 3.3.0, < 3.3.7||>= 3.4.0, < 3.4.5||>= 3.5.0, < 3.5.6||>= 3.6.0, < 3.6.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"fixed","versions":["1.1.1zg","3.0.20","3.3.7","3.4.5","3.5.6","3.6.2"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"1.1.1zg"},{"date":"2026-04-09","kind":"first-observed","version":"3.0.20"},{"date":"2026-04-09","kind":"first-observed","version":"3.3.7"},{"date":"2026-04-09","kind":"first-observed","version":"3.4.5"},{"date":"2026-04-09","kind":"first-observed","version":"3.5.6"},{"date":"2026-04-09","kind":"first-observed","version":"3.6.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.73554,"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-27534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-27534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-27534","date":"2026-10-08","epss":0.02195,"percentile":0.81928}],"risk":0.735325,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-27534","description":"A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user."},"relatedVulnerabilities":[{"id":"CVE-2023-27534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-27534","date":"2026-10-08","epss":0.02195,"percentile":0.81928}],"urls":["https://hackerone.com/reports/1892351","https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/","https://security.gentoo.org/glsa/202310-12","https://security.netapp.com/advisory/ntap-20230420-0012/","https://advisory.splunk.com/advisories/SVD-2023-0809","https://curl.se/docs/CVE-2023-27534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-27534","description":"A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-27534","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-27534","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-27534","date":"2026-10-08","epss":0.02195,"percentile":0.81928}],"risk":0.735325,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-27534","description":"A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user."},"relatedVulnerabilities":[{"id":"CVE-2023-27534","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Secondary","source":"support@hackerone.com"},{"cve":"CVE-2023-27534","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-27534","date":"2026-10-08","epss":0.02195,"percentile":0.81928}],"urls":["https://hackerone.com/reports/1892351","https://lists.debian.org/debian-lts-announce/2024/03/msg00016.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36NBD5YLJXXEDZLDGNFCERWRYJQ6LAQW/","https://security.gentoo.org/glsa/202310-12","https://security.netapp.com/advisory/ntap-20230420-0012/","https://advisory.splunk.com/advisories/SVD-2023-0809","https://curl.se/docs/CVE-2023-27534.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-27534","description":"A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user."}]},{"artifact":{"id":"4afeeed91e127737","cpes":["cpe:2.3:a:libgcc:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-14250","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-14250","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14250","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-14250","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14250","date":"2026-10-08","epss":0.02317,"percentile":0.82913}],"risk":0.7298549999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-14250","description":"This issue resides on libiberty code, a part of binutils, distributed with different versions of RH software. The vulnerability is triggered when the shstrndx (Section Header String Table Index) is zero in the ELF file. This specific condition leads to the integer overflow and subsequent buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2019-14250","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14250","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-14250","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14250","date":"2026-10-08","epss":0.02317,"percentile":0.82913}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html","http://www.securityfocus.com/bid/109354","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924","https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html","https://security.gentoo.org/glsa/202007-39","https://security.netapp.com/advisory/ntap-20190822-0002/","https://usn.ubuntu.com/4326-1/","https://usn.ubuntu.com/4336-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14250","description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow."}]},{"artifact":{"id":"4fd2ded12bcd7931","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-14250","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-14250","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14250","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-14250","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14250","date":"2026-10-08","epss":0.02317,"percentile":0.82913}],"risk":0.7298549999999998,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-14250","description":"This issue resides on libiberty code, a part of binutils, distributed with different versions of RH software. The vulnerability is triggered when the shstrndx (Section Header String Table Index) is zero in the ELF file. This specific condition leads to the integer overflow and subsequent buffer overflow."},"relatedVulnerabilities":[{"id":"CVE-2019-14250","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-14250","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-14250","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-14250","date":"2026-10-08","epss":0.02317,"percentile":0.82913}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html","http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html","http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html","http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html","http://www.securityfocus.com/bid/109354","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924","https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html","https://security.gentoo.org/glsa/202007-39","https://security.netapp.com/advisory/ntap-20190822-0002/","https://usn.ubuntu.com/4326-1/","https://usn.ubuntu.com/4336-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-14250","description":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9076","versionConstraint":">= 1.0.2, < 1.0.2zq||>= 1.1.1, < 1.1.1zh||>= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9076","fix":{"state":"fixed","versions":["1.0.2zq","1.1.1zh","3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"1.0.2zq"},{"date":"2026-06-11","kind":"first-observed","version":"1.1.1zh"},{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"risk":0.72975,"urls":["https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb","https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0","https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98","https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26","https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.19"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69421","versionConstraint":">= 1.0.2, < 1.0.2zn||>= 1.1.1, < 1.1.1ze||>= 3.0.0, < 3.0.19||>= 3.3.0, < 3.3.6||>= 3.4.0, < 3.4.4||>= 3.5.0, < 3.5.5||>= 3.6.0, < 3.6.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69421","fix":{"state":"fixed","versions":["1.0.2zn","1.1.1ze","3.0.19","3.3.6","3.4.4","3.5.5","3.6.1"],"available":[{"date":"2026-01-29","kind":"first-observed","version":"1.0.2zn"},{"date":"2026-01-29","kind":"first-observed","version":"1.1.1ze"},{"date":"2026-01-29","kind":"first-observed","version":"3.0.19"},{"date":"2026-01-29","kind":"first-observed","version":"3.3.6"},{"date":"2026-01-29","kind":"first-observed","version":"3.4.4"},{"date":"2026-01-29","kind":"first-observed","version":"3.5.5"},{"date":"2026-01-29","kind":"first-observed","version":"3.6.1"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69421","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69421","date":"2026-10-08","epss":0.00958,"percentile":0.60302}],"risk":0.7185,"urls":["https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b","https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7","https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd","https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3","https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69421","description":"Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:7.61.1-34.el8_10.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-9086","versionConstraint":"< 0:7.61.1-34.el8_10.9 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-9086","fix":{"state":"fixed","versions":["0:7.61.1-34.el8_10.9"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:7.61.1-34.el8_10.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-9086","date":"2026-10-08","epss":0.01395,"percentile":0.71562}],"risk":0.7184250000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23383","link":"https://access.redhat.com/errata/RHSA-2025:23383"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-9086","description":"An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path."},"relatedVulnerabilities":[{"id":"CVE-2025-9086","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-9086","date":"2026-10-08","epss":0.01395,"percentile":0.71562}],"urls":["https://curl.se/docs/CVE-2025-9086.html","https://curl.se/docs/CVE-2025-9086.json","https://hackerone.com/reports/3294999","http://www.openwall.com/lists/oss-security/2025/09/10/1","https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9086","description":"1. A cookie is set using the `secure` keyword for `https://target`\n2. curl is redirected to or otherwise made to speak with `http://target` (same\n   hostname, but using clear text HTTP) using the same cookie set\n3. The same cookie name is set - but with only a slash as path (`path=\"/\"`).\n   Since this site is not secure, the cookie *should* be ignored.\n4. A bug in the path comparison logic makes curl read outside a heap buffer\n   boundary\n\nThe bug either causes a crash or it potentially makes the comparison come to\nthe wrong conclusion and lets the clear-text site override the contents of the\nsecure cookie, contrary to expectations and depending on the memory contents\nimmediately following the single-byte allocation that holds the path.\n\nThe presumed and correct behavior would be to plainly ignore the second set of\nthe cookie since it was already set as secure on a secure host so overriding\nit on an insecure host should not be okay."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:7.61.1-34.el8_10.9"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9086","versionConstraint":"< 0:7.61.1-34.el8_10.9 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-9086","fix":{"state":"fixed","versions":["0:7.61.1-34.el8_10.9"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:7.61.1-34.el8_10.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-9086","date":"2026-10-08","epss":0.01395,"percentile":0.71562}],"risk":0.7184250000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23383","link":"https://access.redhat.com/errata/RHSA-2025:23383"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-9086","description":"An out of bounds read flaw has been discovered in the curl project. Under specific conditions the path comparison logic makes curl read outside a heap buffer boundary. This bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path."},"relatedVulnerabilities":[{"id":"CVE-2025-9086","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-9086","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-9086","date":"2026-10-08","epss":0.01395,"percentile":0.71562}],"urls":["https://curl.se/docs/CVE-2025-9086.html","https://curl.se/docs/CVE-2025-9086.json","https://hackerone.com/reports/3294999","http://www.openwall.com/lists/oss-security/2025/09/10/1","https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9086","description":"1. A cookie is set using the `secure` keyword for `https://target`\n2. curl is redirected to or otherwise made to speak with `http://target` (same\n   hostname, but using clear text HTTP) using the same cookie set\n3. The same cookie name is set - but with only a slash as path (`path=\"/\"`).\n   Since this site is not secure, the cookie *should* be ignored.\n4. A bug in the path comparison logic makes curl read outside a heap buffer\n   boundary\n\nThe bug either causes a crash or it potentially makes the comparison come to\nthe wrong conclusion and lets the clear-text site override the contents of the\nsecure cookie, contrary to expectations and depending on the memory contents\nimmediately following the single-byte allocation that holds the path.\n\nThe presumed and correct behavior would be to plainly ignore the second set of\nthe cookie since it was already set as secure on a secure host so overriding\nit on an insecure host should not be okay."}]},{"artifact":{"id":"3dd1075e2b063a17","cpes":["cpe:2.3:a:libtasn1:libtasn1:4.13-5.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libtasn1:4.13-5.el8_10:*:*:*:*:*:*:*"],"name":"libtasn1","purl":"pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libtasn1-4.13-5.el8_10.src.rpm","type":"rpm","version":"4.13-5.el8_10","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-1000654","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libtasn1","version":"0:4.13-5.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-1000654","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-1000654","date":"2026-10-08","epss":0.02008,"percentile":0.80238}],"risk":0.7028,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-1000654","description":"A vulnerability was found in GNU Libtasn1, where a resource management issue can lead to a denial of service, here an attacker could exploit this flaw by persuading a victim to parse a specially crafted file, exhausting all available CPU resources."},"relatedVulnerabilities":[{"id":"CVE-2018-1000654","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.1,"impactScore":6.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2018-1000654","date":"2026-10-08","epss":0.02008,"percentile":0.80238}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00018.html","http://www.securityfocus.com/bid/105151","https://gitlab.com/gnutls/libtasn1/issues/4","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000654","description":"GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.695765,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7210","description":"A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.695765,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7210","description":"A flaw was found in the `python` and `expat` components. Insufficient entropy in the hash-flooding protection mechanism of `xml.parsers.expat` and `xml.etree.ElementTree` allows a remote attacker to craft a malicious XML document. This crafted document can trigger a hash flooding attack, leading to a denial of service (DoS) condition."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-21.el8_10.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-49794","versionConstraint":"< 0:2.9.7-21.el8_10.1 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-49794","fix":{"state":"fixed","versions":["0:2.9.7-21.el8_10.1"],"available":[{"date":"2025-07-10","kind":"first-observed","version":"0:2.9.7-21.el8_10.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49794","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-49794","date":"2026-10-08","epss":0.00833,"percentile":0.56358}],"risk":0.69139,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10698","link":"https://access.redhat.com/errata/RHSA-2025:10698"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-49794","description":"A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path=\"...\"/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors."},"relatedVulnerabilities":[{"id":"CVE-2025-49794","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-49794","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-49794","date":"2026-10-08","epss":0.00833,"percentile":0.56358}],"urls":["https://access.redhat.com/errata/RHSA-2025:10630","https://access.redhat.com/errata/RHSA-2025:10698","https://access.redhat.com/errata/RHSA-2025:10699","https://access.redhat.com/errata/RHSA-2025:11580","https://access.redhat.com/errata/RHSA-2025:12098","https://access.redhat.com/errata/RHSA-2025:12099","https://access.redhat.com/errata/RHSA-2025:12199","https://access.redhat.com/errata/RHSA-2025:12237","https://access.redhat.com/errata/RHSA-2025:12239","https://access.redhat.com/errata/RHSA-2025:12240","https://access.redhat.com/errata/RHSA-2025:12241","https://access.redhat.com/errata/RHSA-2025:13335","https://access.redhat.com/errata/RHSA-2025:15397","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:18217","https://access.redhat.com/errata/RHSA-2025:18218","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:18240","https://access.redhat.com/errata/RHSA-2025:19020","https://access.redhat.com/errata/RHSA-2025:19041","https://access.redhat.com/errata/RHSA-2025:19046","https://access.redhat.com/errata/RHSA-2025:19894","https://access.redhat.com/errata/RHSA-2025:21913","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2025-49794","https://bugzilla.redhat.com/show_bug.cgi?id=2372373","https://gitlab.gnome.org/GNOME/libxml2/-/issues/931","https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-49794","description":"A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path=\"...\"/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42010","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42010","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42010","date":"2026-10-08","epss":0.00944,"percentile":0.59864}],"risk":0.68912,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42010","description":"A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process."},"relatedVulnerabilities":[{"id":"CVE-2026-42010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-42010","cwe":"CWE-626","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-42010","cwe":"CWE-170","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42010","date":"2026-10-08","epss":0.00944,"percentile":0.59864}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34764","https://access.redhat.com/errata/RHSA-2026:34788","https://access.redhat.com/errata/RHSA-2026:34790","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42010","https://bugzilla.redhat.com/show_bug.cgi?id=2467289","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42010","description":"A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-63072","versionConstraint":">= 1.1.1, < 1.1.1zi||>= 3.0.0, < 3.0.22||>= 3.4.0, < 3.4.7||>= 3.5.0, < 3.5.8||>= 3.6.0, < 3.6.4||>= 4.0.0, < 4.0.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"fixed","versions":["1.1.1zi","3.0.22","3.4.7","3.5.8","3.6.4","4.0.2"],"available":[{"date":"2026-08-29","kind":"first-observed","version":"1.1.1zi"},{"date":"2026-08-29","kind":"first-observed","version":"3.0.22"},{"date":"2026-08-29","kind":"first-observed","version":"3.4.7"},{"date":"2026-08-29","kind":"first-observed","version":"3.5.8"},{"date":"2026-08-29","kind":"first-observed","version":"3.6.4"},{"date":"2026-08-29","kind":"first-observed","version":"4.0.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.6869999999999999,"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.19"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69420","versionConstraint":">= 1.1.1, < 1.1.1ze||>= 3.0.0, < 3.0.19||>= 3.3.0, < 3.3.6||>= 3.4.0, < 3.4.4||>= 3.5.0, < 3.5.5||>= 3.6.0, < 3.6.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69420","fix":{"state":"fixed","versions":["1.1.1ze","3.0.19","3.3.6","3.4.4","3.5.5","3.6.1"],"available":[{"date":"2026-01-29","kind":"first-observed","version":"1.1.1ze"},{"date":"2026-01-29","kind":"first-observed","version":"3.0.19"},{"date":"2026-01-29","kind":"first-observed","version":"3.3.6"},{"date":"2026-01-29","kind":"first-observed","version":"3.4.4"},{"date":"2026-01-29","kind":"first-observed","version":"3.5.5"},{"date":"2026-01-29","kind":"first-observed","version":"3.6.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69420","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69420","date":"2026-10-08","epss":0.00899,"percentile":0.58405}],"risk":0.67425,"urls":["https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9","https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a","https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e","https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b","https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69420","description":"Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"086f3776fe66338d","cpes":["cpe:2.3:a:libnghttp2:libnghttp2:1.33.0-6.el8_10.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libnghttp2:1.33.0-6.el8_10.1:*:*:*:*:*:*:*"],"name":"libnghttp2","purl":"pkg:rpm/redhat/libnghttp2@1.33.0-6.el8_10.1?arch=x86_64&distro=rhel-8.10&upstream=nghttp2-1.33.0-6.el8_10.1.src.rpm","type":"rpm","version":"1.33.0-6.el8_10.1","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nghttp2","version":"1.33.0-6.el8_10.1"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.33.0-6.el8_10.2"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27135","versionConstraint":"< 0:1.33.0-6.el8_10.2 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"nghttp2","version":"1.33.0-6.el8_10.1"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-27135","fix":{"state":"fixed","versions":["0:1.33.0-6.el8_10.2"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:1.33.0-6.el8_10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27135","date":"2026-10-08","epss":0.00892,"percentile":0.58186}],"risk":0.669,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:7667","link":"https://access.redhat.com/errata/RHSA-2026:7667"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-27135","description":"A flaw was found in nghttp2. Due to missing internal state validation, the library continues to process incoming data even after a session has been terminated. A remote attacker could exploit this by sending a specially crafted HTTP/2 frame, leading to an assertion failure and a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-27135","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-27135","cwe":"CWE-617","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27135","date":"2026-10-08","epss":0.00892,"percentile":0.58186}],"urls":["https://github.com/nghttp2/nghttp2/commit/5c7df8fa815ac1004d9ecb9d1f7595c4d37f46e1","https://github.com/nghttp2/nghttp2/security/advisories/GHSA-6933-cjhr-5qg6","http://www.openwall.com/lists/oss-security/2026/03/20/3","https://lists.debian.org/debian-lts-announce/2026/05/msg00025.html","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14773","https://access.redhat.com/errata/RHSA-2026:14937","https://access.redhat.com/errata/RHSA-2026:15087","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:17596","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:20040","https://access.redhat.com/errata/RHSA-2026:20087","https://access.redhat.com/errata/RHSA-2026:21656","https://access.redhat.com/errata/RHSA-2026:21690","https://access.redhat.com/errata/RHSA-2026:21695","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:27200","https://access.redhat.com/errata/RHSA-2026:27201","https://access.redhat.com/errata/RHSA-2026:6190","https://access.redhat.com/errata/RHSA-2026:7080","https://access.redhat.com/errata/RHSA-2026:7123","https://access.redhat.com/errata/RHSA-2026:7302","https://access.redhat.com/errata/RHSA-2026:7310","https://access.redhat.com/errata/RHSA-2026:7350","https://access.redhat.com/errata/RHSA-2026:7666","https://access.redhat.com/errata/RHSA-2026:7667","https://access.redhat.com/errata/RHSA-2026:7668","https://access.redhat.com/errata/RHSA-2026:7670","https://access.redhat.com/errata/RHSA-2026:7675","https://access.redhat.com/errata/RHSA-2026:7896","https://access.redhat.com/errata/RHSA-2026:7983","https://access.redhat.com/errata/RHSA-2026:8339","https://access.redhat.com/errata/RHSA-2026:8538","https://access.redhat.com/errata/RHSA-2026:8539","https://access.redhat.com/errata/RHSA-2026:8540","https://access.redhat.com/errata/RHSA-2026:8541","https://access.redhat.com/errata/RHSA-2026:8545","https://access.redhat.com/errata/RHSA-2026:8546","https://access.redhat.com/errata/RHSA-2026:8547","https://access.redhat.com/errata/RHSA-2026:8548","https://access.redhat.com/errata/RHSA-2026:8868","https://access.redhat.com/errata/RHSA-2026:9711","https://access.redhat.com/errata/RHSA-2026:9832","https://access.redhat.com/errata/RHSA-2026:9874","https://access.redhat.com/security/cve/CVE-2026-27135","https://bugzilla.redhat.com/show_bug.cgi?id=2448754","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27135.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27135","description":"nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called internally by the library when it detects the situation that is subject to connection error. Due to the missing internal state validation, the library keeps reading the rest of the data after one of those APIs is called. Then receiving a malformed frame that causes FRAME_SIZE_ERROR causes assertion failure. nghttp2 v1.68.1 adds missing state validation to avoid assertion failure. No known workarounds are available."}]},{"artifact":{"id":"d6198730eb90fd58","cpes":["cpe:2.3:a:jline-remote-telnet:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote-telnet:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*"],"name":"jline-remote-telnet","purl":"pkg:maven/org.jline/jline-remote-telnet@3.25.1","type":"java-archive","version":"3.25.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.25.1.jar:org.jline:jline-remote-telnet","manifestName":"","pomArtifactID":"jline-remote-telnet","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.25.1.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jline-3.25.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2r2c-cx56-8933","versionConstraint":"<3.30.14 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-remote-telnet","version":"3.25.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-2r2c-cx56-8933","fix":{"state":"fixed","versions":["3.30.14"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"3.30.14"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56741","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56741","date":"2026-10-08","epss":0.00889,"percentile":0.58096}],"risk":0.66675,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933","https://nvd.nist.gov/vuln/detail/CVE-2026-56741","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708","https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e","https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2r2c-cx56-8933","description":"JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry"},"relatedVulnerabilities":[{"id":"CVE-2026-56741","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56741","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56741","date":"2026-10-08","epss":0.00889,"percentile":0.58096}],"urls":["https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708","https://github.com/jline/jline3/commit/733eb353dca7b0ea0252e724445b6defa29c393e","https://github.com/jline/jline3/commit/86b7ba7801988aadb1a67555629522a71d603bd3","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1","https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56741","description":"JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33845","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-33845","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-08","epss":0.00886,"percentile":0.58022}],"risk":0.6645,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-33845","description":"A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-33845","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-33845","cwe":"CWE-191","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33845","date":"2026-10-08","epss":0.00886,"percentile":0.58022}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:34372","https://access.redhat.com/errata/RHSA-2026:36004","https://access.redhat.com/errata/RHSA-2026:36005","https://access.redhat.com/errata/RHSA-2026:36006","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-33845","https://bugzilla.redhat.com/show_bug.cgi?id=2450624","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33845.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33845","description":"A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service."}]},{"artifact":{"id":"d6198730eb90fd58","cpes":["cpe:2.3:a:jline-remote-telnet:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote-telnet:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote_telnet:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-remote:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_remote:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-remote-telnet:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_remote_telnet:3.25.1:*:*:*:*:*:*:*"],"name":"jline-remote-telnet","purl":"pkg:maven/org.jline/jline-remote-telnet@3.25.1","type":"java-archive","version":"3.25.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.25.1.jar:org.jline:jline-remote-telnet","manifestName":"","pomArtifactID":"jline-remote-telnet","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.25.1.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jline-3.25.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.14"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-47qp-hqvx-6r3f","versionConstraint":"<3.30.14 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-remote-telnet","version":"3.25.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-47qp-hqvx-6r3f","fix":{"state":"fixed","versions":["3.30.14"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"3.30.14"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56740","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56740","date":"2026-10-08","epss":0.00884,"percentile":0.57976}],"risk":0.663,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f","https://nvd.nist.gov/vuln/detail/CVE-2026-56740","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/pull/2001","https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09","https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40","https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1","https://github.com/jline/jline3/releases/tag/jline-3.30.14"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-47qp-hqvx-6r3f","description":"JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables"},"relatedVulnerabilities":[{"id":"CVE-2026-56740","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56740","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-56740","date":"2026-10-08","epss":0.00884,"percentile":0.57976}],"urls":["https://github.com/jline/jline3/commit/0389f0ee6d0375901b602671ad5dafd4d1d4ee09","https://github.com/jline/jline3/commit/4ee3a73849ffb9a85ec748e4e8cd8f6d81f84f40","https://github.com/jline/jline3/commit/934f09e6128cee33c2b13d42b6e859c1ee2d194b","https://github.com/jline/jline3/pull/2000","https://github.com/jline/jline3/pull/2001","https://github.com/jline/jline3/releases/tag/4.0.16","https://github.com/jline/jline3/releases/tag/4.2.1","https://github.com/jline/jline3/releases/tag/jline-3.30.14","https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56740","description":"JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1."}]},{"artifact":{"id":"7b479e2b1ed0e25e","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.34-5.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=libpng-1.6.34-5.el8.src.rpm","type":"rpm","version":"2:1.6.34-5.el8","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.34-11.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33416","versionConstraint":"< 2:1.6.34-11.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libpng","version":"2:1.6.34-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-33416","fix":{"state":"fixed","versions":["2:1.6.34-11.el8_10"],"available":[{"date":"2026-06-25","kind":"first-observed","version":"2:1.6.34-11.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33416","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33416","date":"2026-10-08","epss":0.01052,"percentile":0.63289}],"risk":0.6575,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:29898","link":"https://access.redhat.com/errata/RHSA-2026:29898"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-33416","description":"A flaw was found in libpng, a library used for processing PNG (Portable Network Graphics) image files. This vulnerability arises from improper memory management where a heap-allocated buffer is aliased between internal data structures. When specific functions are called, a freed memory region can still be referenced, leading to a use-after-free condition. An attacker could potentially exploit this to achieve arbitrary code execution or cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-33416","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33416","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33416","date":"2026-10-08","epss":0.01052,"percentile":0.63289}],"urls":["https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb","https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667","https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25","https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1","https://github.com/pnggroup/libpng/pull/824","https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33416","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set_PLTE` has the same effect, because both functions call `png_free_data` internally before reallocating the `info_ptr` buffer. Version 1.6.56 fixes the issue."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-0465","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-0465","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0465","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0465","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0465","date":"2026-10-08","epss":0.01583,"percentile":0.74801}],"risk":0.6569450000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-0465","description":"A flaw was found in OpenSSL. Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. OpenSSL and other certificate policy checks silently ignore invalid certificate policies in leaf certificates that are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function."},"relatedVulnerabilities":[{"id":"CVE-2023-0465","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-0465","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2023-0465","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2023-0465","date":"2026-10-08","epss":0.01583,"percentile":0.74801}],"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=10325176f3d3e98c6e2b3bf5ab1e3b334de6947a","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1dd43e0709fece299b15208f36cc7c76209ba0bb","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=b013765abfa80036dc779dd0e50602c57bb3bf95","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=facfb1ab745646e97a1920977ae4a9965ea61d5c","https://lists.debian.org/debian-lts-announce/2023/06/msg00011.html","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230414-0001/","https://www.debian.org/security/2023/dsa-5417","https://www.openssl.org/news/secadv/20230328.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-0465","description":"Applications that use a non-default option when verifying certificates may be\nvulnerable to an attack from a malicious CA to circumvent certain checks.\n\nInvalid certificate policies in leaf certificates are silently ignored by\nOpenSSL and other certificate policy checks are skipped for that certificate.\nA malicious CA could use this to deliberately assert invalid certificate policies\nin order to circumvent policy checking on the certificate altogether.\n\nPolicy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.11"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-4807","versionConstraint":">= 1.1.1, < 1.1.1w||>= 3.0.0, < 3.0.11||>= 3.1.0, < 3.1.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-4807","fix":{"state":"fixed","versions":["1.1.1w","3.0.11","3.1.3"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.1.1w"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.11"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-4807","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2023-4807","date":"2026-10-08","epss":0.00843,"percentile":0.56656}],"risk":0.644895,"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=4bfac4471f53c4f74c8d81020beb938f92d84ca5","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=6754de4a121ec7f261b16723180df6592cbb4508","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a632d534c73eeb3e3db8c7540d811194ef7c79ff","https://www.openssl.org/news/secadv/20230908.txt","https://security.netapp.com/advisory/ntap-20230921-0001/"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-4807","description":"Issue summary: The POLY1305 MAC (message authentication code) implementation\ncontains a bug that might corrupt the internal state of applications on the\nWindows 64 platform when running on newer X86_64 processors supporting the\nAVX512-IFMA instructions.\n\nImpact summary: If in an application that uses the OpenSSL library an attacker\ncan influence whether the POLY1305 MAC algorithm is used, the application\nstate might be corrupted with various application dependent consequences.\n\nThe POLY1305 MAC (message authentication code) implementation in OpenSSL does\nnot save the contents of non-volatile XMM registers on Windows 64 platform\nwhen calculating the MAC of data larger than 64 bytes. Before returning to\nthe caller all the XMM registers are set to zero rather than restoring their\nprevious content. The vulnerable code is used only on newer x86_64 processors\nsupporting the AVX512-IFMA instructions.\n\nThe consequences of this kind of internal application state corruption can\nbe various - from no consequences, if the calling application does not\ndepend on the contents of non-volatile XMM registers at all, to the worst\nconsequences, where the attacker could get complete control of the application\nprocess. However given the contents of the registers are just zeroized so\nthe attacker cannot put arbitrary values inside, the most likely consequence,\nif any, would be an incorrect result of some application dependent\ncalculations or a crash leading to a denial of service.\n\nThe POLY1305 MAC algorithm is most frequently used as part of the\nCHACHA20-POLY1305 AEAD (authenticated encryption with associated data)\nalgorithm. The most common usage of this AEAD cipher is with TLS protocol\nversions 1.2 and 1.3 and a malicious client can influence whether this AEAD\ncipher is used by the server. This implies that server applications using\nOpenSSL can be potentially impacted. However we are currently not aware of\nany concrete application that would be affected by this issue therefore we\nconsider this a Low severity security issue.\n\nAs a workaround the AVX512-IFMA instructions support can be disabled at\nruntime by setting the environment variable OPENSSL_ia32cap:\n\n   OPENSSL_ia32cap=:~0x200000\n\nThe FIPS provider is not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"0b18af35df5be7b3","cpes":["cpe:2.3:a:redhat:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:wget:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=rhel-8.10&upstream=wget-1.19.5-12.el8_10.src.rpm","type":"rpm","version":"1.19.5-12.el8_10","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-31879","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"wget","version":"0:1.19.5-12.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-31879","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"risk":0.6347999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-31879","description":"A flaw was found in wget. If wget sends an Authorization header as part of a query and receives an HTTP REDIRECT to a third party in return, the Authorization header will be forwarded as part of the redirected request. This issue creates a password leak, as the second server receives the password. The highest threat from this vulnerability is confidentiality."},"relatedVulnerabilities":[{"id":"CVE-2021-31879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"urls":["https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html","https://security.netapp.com/advisory/ntap-20210618-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5260","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5260","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5260","date":"2026-10-08","epss":0.00945,"percentile":0.59888}],"risk":0.6236999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5260","description":"A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5260","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5260","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5260","date":"2026-10-08","epss":0.00945,"percentile":0.59888}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:67837","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5260","https://bugzilla.redhat.com/show_bug.cgi?id=2467450","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-10"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5260","description":"A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure."}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3731","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3731","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"risk":0.6180000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3731","description":"A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name` or `sftp_extensions_get_data` functions. This could lead to a Denial of Service (DoS), making the affected system unresponsive."},"relatedVulnerabilities":[{"id":"CVE-2026-3731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"urls":["https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60","https://vuldb.com/?ctiid.349709","https://vuldb.com/?id.349709","https://vuldb.com/?submit.767120","https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz","https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3731","description":"A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3731","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3731","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"risk":0.6180000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3731","description":"A flaw was found in libssh. A remote attacker could trigger an out-of-bounds read vulnerability in the SFTP Extension Name Handler by manipulating the `idx` argument in the `sftp_extensions_get_name` or `sftp_extensions_get_data` functions. This could lead to a Denial of Service (DoS), making the affected system unresponsive."},"relatedVulnerabilities":[{"id":"CVE-2026-3731","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3731","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-3731","cwe":"CWE-125","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-3731","date":"2026-10-08","epss":0.012,"percentile":0.67273}],"urls":["https://gitlab.com/libssh/libssh-mirror/-/commit/855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60","https://vuldb.com/?ctiid.349709","https://vuldb.com/?id.349709","https://vuldb.com/?submit.767120","https://www.libssh.org/files/0.12/libssh-0.12.0.tar.xz","https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3731","description":"A weakness has been identified in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read. The attack may be performed from remote. Upgrading to version 0.11.4 and 0.12.0 is sufficient to resolve this issue. This patch is called 855a0853ad3abd4a6cd85ce06fce6d8d4c7a0b60. You should upgrade the affected component."}]},{"artifact":{"id":"0b18af35df5be7b3","cpes":["cpe:2.3:a:redhat:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:wget:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=rhel-8.10&upstream=wget-1.19.5-12.el8_10.src.rpm","type":"rpm","version":"1.19.5-12.el8_10","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-10524","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"wget","version":"0:1.19.5-12.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-10524","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"risk":0.615825,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-10524","description":"A flaw was found in the Wget package. Wget might issue an FTP request to a different host in configurations where the HTTP shorthand format is used with user-provided input. An attacker may be able to use specially crafted input to cause Wget to access an arbitrary host."},"relatedVulnerabilities":[{"id":"CVE-2024-10524","cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"urls":["https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778","https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/","https://seclists.org/oss-sec/2024/q4/107","http://www.openwall.com/lists/oss-security/2024/11/18/6","https://security.netapp.com/advisory/ntap-20250321-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."}]},{"artifact":{"id":"8ab0f0f754c8b1e4","cpes":["cpe:2.3:a:libgcrypt:libgcrypt:1.8.5-7.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcrypt:1.8.5-7.el8_6:*:*:*:*:*:*:*"],"name":"libgcrypt","purl":"pkg:rpm/redhat/libgcrypt@1.8.5-7.el8_6?arch=x86_64&distro=rhel-8.10&upstream=libgcrypt-1.8.5-7.el8_6.src.rpm","type":"rpm","version":"1.8.5-7.el8_6","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-2236","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libgcrypt","version":"0:1.8.5-7.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-2236","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-08","epss":0.01114,"percentile":0.65005}],"risk":0.6071300000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."},"relatedVulnerabilities":[{"id":"CVE-2024-2236","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-2236","cwe":"CWE-385","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-2236","date":"2026-10-08","epss":0.01114,"percentile":0.65005}],"urls":["https://access.redhat.com/errata/RHSA-2024:9404","https://access.redhat.com/errata/RHSA-2025:3530","https://access.redhat.com/errata/RHSA-2025:3534","https://access.redhat.com/security/cve/CVE-2024-2236","https://bugzilla.redhat.com/show_bug.cgi?id=2245218","https://bugzilla.redhat.com/show_bug.cgi?id=2268268"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-2236","description":"A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42766","versionConstraint":">= 1.0.2, < 1.0.2zq||>= 1.1.1, < 1.1.1zh||>= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42766","fix":{"state":"fixed","versions":["1.0.2zq","1.1.1zh","3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"1.0.2zq"},{"date":"2026-06-11","kind":"first-observed","version":"1.1.1zh"},{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"risk":0.6049500000000001,"urls":["https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce","https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4","https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7","https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4","https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.20"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-28390","versionConstraint":">= 1.0.2, < 1.0.2zp||>= 1.1.1, < 1.1.1zg||>= 3.0.0, < 3.0.20||>= 3.3.0, < 3.3.7||>= 3.4.0, < 3.4.5||>= 3.5.0, < 3.5.6||>= 3.6.0, < 3.6.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-28390","fix":{"state":"fixed","versions":["1.0.2zp","1.1.1zg","3.0.20","3.3.7","3.4.5","3.5.6","3.6.2"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"1.0.2zp"},{"date":"2026-04-09","kind":"first-observed","version":"1.1.1zg"},{"date":"2026-04-09","kind":"first-observed","version":"3.0.20"},{"date":"2026-04-09","kind":"first-observed","version":"3.3.7"},{"date":"2026-04-09","kind":"first-observed","version":"3.4.5"},{"date":"2026-04-09","kind":"first-observed","version":"3.5.6"},{"date":"2026-04-09","kind":"first-observed","version":"3.6.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"risk":0.6037499999999999,"urls":["https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc","https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6","https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4","https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788","https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-11053","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-11053","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"risk":0.5998600000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-11053","description":"A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host."},"relatedVulnerabilities":[{"id":"CVE-2024-11053","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":3.4,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"urls":["https://curl.se/docs/CVE-2024-11053.html","https://curl.se/docs/CVE-2024-11053.json","https://hackerone.com/reports/2829063","http://www.openwall.com/lists/oss-security/2024/12/11/1","https://security.netapp.com/advisory/ntap-20250124-0012/","https://security.netapp.com/advisory/ntap-20250131-0003/","https://security.netapp.com/advisory/ntap-20250131-0004/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-11053","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-11053","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-11053","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"risk":0.5998600000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-11053","description":"A flaw was found in curl. A logic error when processing credentials from the .netrc file while performing redirects allows the transfer of credentials from the original host to the followed-to host under certain circumstances, leaking the credentials to the followed-to host."},"relatedVulnerabilities":[{"id":"CVE-2024-11053","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N","metrics":{"baseScore":3.4,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-11053","date":"2026-10-08","epss":0.01348,"percentile":0.7063}],"urls":["https://curl.se/docs/CVE-2024-11053.html","https://curl.se/docs/CVE-2024-11053.json","https://hackerone.com/reports/2829063","http://www.openwall.com/lists/oss-security/2024/12/11/1","https://security.netapp.com/advisory/ntap-20250124-0012/","https://security.netapp.com/advisory/ntap-20250131-0003/","https://security.netapp.com/advisory/ntap-20250131-0004/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-11053","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password."}]},{"artifact":{"id":"fa819346ba1b9bc6","cpes":["cpe:2.3:a:systemd:systemd:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:rpm/redhat/systemd@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-4598","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"0:239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4598","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4598","cwe":"CWE-364","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4598","date":"2026-10-08","epss":0.01233,"percentile":0.68108}],"risk":0.598005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4598","description":"A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality."},"relatedVulnerabilities":[{"id":"CVE-2025-4598","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4598","cwe":"CWE-364","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4598","date":"2026-10-08","epss":0.01233,"percentile":0.68108}],"urls":["https://access.redhat.com/errata/RHSA-2025:22660","https://access.redhat.com/errata/RHSA-2025:22868","https://access.redhat.com/errata/RHSA-2025:23227","https://access.redhat.com/errata/RHSA-2025:23234","https://access.redhat.com/errata/RHSA-2026:0414","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:18153","https://access.redhat.com/security/cve/CVE-2025-4598","https://bugzilla.redhat.com/show_bug.cgi?id=2369242","https://www.openwall.com/lists/oss-security/2025/05/29/3","http://seclists.org/fulldisclosure/2025/Jun/9","http://www.openwall.com/lists/oss-security/2025/06/05/1","http://www.openwall.com/lists/oss-security/2025/06/05/3","http://www.openwall.com/lists/oss-security/2025/08/18/3","https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598","https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/","https://lists.debian.org/debian-lts-announce/2025/07/msg00022.html","https://www.openwall.com/lists/oss-security/2025/08/18/3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4598","description":"A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality."}]},{"artifact":{"id":"35ec2c60a4c27ac2","cpes":["cpe:2.3:a:systemd-libs:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd-libs:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_libs:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-libs:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_libs:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd-libs","purl":"pkg:rpm/redhat/systemd-libs@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"239-82.el8_10.5"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4598","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4598","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4598","cwe":"CWE-364","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4598","date":"2026-10-08","epss":0.01233,"percentile":0.68108}],"risk":0.598005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4598","description":"A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality."},"relatedVulnerabilities":[{"id":"CVE-2025-4598","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4598","cwe":"CWE-364","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4598","date":"2026-10-08","epss":0.01233,"percentile":0.68108}],"urls":["https://access.redhat.com/errata/RHSA-2025:22660","https://access.redhat.com/errata/RHSA-2025:22868","https://access.redhat.com/errata/RHSA-2025:23227","https://access.redhat.com/errata/RHSA-2025:23234","https://access.redhat.com/errata/RHSA-2026:0414","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:18153","https://access.redhat.com/security/cve/CVE-2025-4598","https://bugzilla.redhat.com/show_bug.cgi?id=2369242","https://www.openwall.com/lists/oss-security/2025/05/29/3","http://seclists.org/fulldisclosure/2025/Jun/9","http://www.openwall.com/lists/oss-security/2025/06/05/1","http://www.openwall.com/lists/oss-security/2025/06/05/3","http://www.openwall.com/lists/oss-security/2025/08/18/3","https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598","https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/","https://lists.debian.org/debian-lts-announce/2025/07/msg00022.html","https://www.openwall.com/lists/oss-security/2025/08/18/3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4598","description":"A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality."}]},{"artifact":{"id":"3072771f0e906f1d","cpes":["cpe:2.3:a:systemd-pam:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd-pam:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd_pam:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd-pam:239-82.el8_10.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:systemd_pam:239-82.el8_10.5:*:*:*:*:*:*:*"],"name":"systemd-pam","purl":"pkg:rpm/redhat/systemd-pam@239-82.el8_10.5?arch=x86_64&distro=rhel-8.10&upstream=systemd-239-82.el8_10.5.src.rpm","type":"rpm","version":"239-82.el8_10.5","language":"","licenses":["LGPLv2+ and MIT and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"systemd","version":"239-82.el8_10.5"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4598","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"systemd","version":"239-82.el8_10.5"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4598","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4598","cwe":"CWE-364","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4598","date":"2026-10-08","epss":0.01233,"percentile":0.68108}],"risk":0.598005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4598","description":"A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality."},"relatedVulnerabilities":[{"id":"CVE-2025-4598","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4598","cwe":"CWE-364","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4598","date":"2026-10-08","epss":0.01233,"percentile":0.68108}],"urls":["https://access.redhat.com/errata/RHSA-2025:22660","https://access.redhat.com/errata/RHSA-2025:22868","https://access.redhat.com/errata/RHSA-2025:23227","https://access.redhat.com/errata/RHSA-2025:23234","https://access.redhat.com/errata/RHSA-2026:0414","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:18153","https://access.redhat.com/security/cve/CVE-2025-4598","https://bugzilla.redhat.com/show_bug.cgi?id=2369242","https://www.openwall.com/lists/oss-security/2025/05/29/3","http://seclists.org/fulldisclosure/2025/Jun/9","http://www.openwall.com/lists/oss-security/2025/06/05/1","http://www.openwall.com/lists/oss-security/2025/06/05/3","http://www.openwall.com/lists/oss-security/2025/08/18/3","https://blogs.oracle.com/linux/post/analysis-of-cve-2025-4598","https://ciq.com/blog/the-real-danger-of-systemd-coredump-cve-2025-4598/","https://lists.debian.org/debian-lts-announce/2025/07/msg00022.html","https://www.openwall.com/lists/oss-security/2025/08/18/3","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4598","description":"A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process.\n\nA SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-76.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6100","versionConstraint":"< 0:3.6.8-76.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6100","fix":{"state":"fixed","versions":["0:3.6.8-76.el8_10"],"available":[{"date":"2026-04-28","kind":"first-observed","version":"0:3.6.8-76.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6100","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-787","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6100","date":"2026-10-08","epss":0.00761,"percentile":0.53914}],"risk":0.59358,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:11077","link":"https://access.redhat.com/errata/RHSA-2026:11077"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6100","description":"A flaw was found in Python's decompression modules, including `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile`. This vulnerability, a use-after-free, can occur if a program attempts to re-use a decompression object after a memory allocation error, especially when the system is experiencing high memory usage. Exploitation of this flaw could potentially allow an attacker to execute arbitrary code or access sensitive data. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable."},"relatedVulnerabilities":[{"id":"CVE-2026-6100","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6100","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-787","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6100","date":"2026-10-08","epss":0.00761,"percentile":0.53914}],"urls":["https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e","https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d","https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2","https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20","https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b","https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3","https://github.com/python/cpython/issues/148395","https://github.com/python/cpython/pull/148396","https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/","http://www.openwall.com/lists/oss-security/2026/04/13/10","https://access.redhat.com/errata/RHSA-2026:10117","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10711","https://access.redhat.com/errata/RHSA-2026:10745","https://access.redhat.com/errata/RHSA-2026:10774","https://access.redhat.com/errata/RHSA-2026:10949","https://access.redhat.com/errata/RHSA-2026:10950","https://access.redhat.com/errata/RHSA-2026:11062","https://access.redhat.com/errata/RHSA-2026:11077","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:13692","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14652","https://access.redhat.com/errata/RHSA-2026:14653","https://access.redhat.com/errata/RHSA-2026:14656","https://access.redhat.com/errata/RHSA-2026:16699","https://access.redhat.com/errata/RHSA-2026:17525","https://access.redhat.com/errata/RHSA-2026:17619","https://access.redhat.com/errata/RHSA-2026:19019","https://access.redhat.com/errata/RHSA-2026:19064","https://access.redhat.com/errata/RHSA-2026:19175","https://access.redhat.com/errata/RHSA-2026:19176","https://access.redhat.com/errata/RHSA-2026:19177","https://access.redhat.com/errata/RHSA-2026:19216","https://access.redhat.com/errata/RHSA-2026:19549","https://access.redhat.com/errata/RHSA-2026:19570","https://access.redhat.com/errata/RHSA-2026:19571","https://access.redhat.com/errata/RHSA-2026:19576","https://access.redhat.com/errata/RHSA-2026:19590","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:21682","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:26187","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:52400","https://access.redhat.com/errata/RHSA-2026:8822","https://access.redhat.com/errata/RHSA-2026:8824","https://access.redhat.com/errata/RHSA-2026:9228","https://access.redhat.com/security/cve/CVE-2026-6100","https://bugzilla.redhat.com/show_bug.cgi?id=2457932","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6100","description":"Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.\n\nThe vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-76.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6100","versionConstraint":"< 0:3.6.8-76.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6100","fix":{"state":"fixed","versions":["0:3.6.8-76.el8_10"],"available":[{"date":"2026-04-28","kind":"first-observed","version":"0:3.6.8-76.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6100","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-787","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6100","date":"2026-10-08","epss":0.00761,"percentile":0.53914}],"risk":0.59358,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:11077","link":"https://access.redhat.com/errata/RHSA-2026:11077"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6100","description":"A flaw was found in Python's decompression modules, including `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile`. This vulnerability, a use-after-free, can occur if a program attempts to re-use a decompression object after a memory allocation error, especially when the system is experiencing high memory usage. Exploitation of this flaw could potentially allow an attacker to execute arbitrary code or access sensitive data. The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable."},"relatedVulnerabilities":[{"id":"CVE-2026-6100","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6100","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-787","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6100","cwe":"CWE-825","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-6100","date":"2026-10-08","epss":0.00761,"percentile":0.53914}],"urls":["https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e","https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d","https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2","https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20","https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b","https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3","https://github.com/python/cpython/issues/148395","https://github.com/python/cpython/pull/148396","https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/","http://www.openwall.com/lists/oss-security/2026/04/13/10","https://access.redhat.com/errata/RHSA-2026:10117","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10711","https://access.redhat.com/errata/RHSA-2026:10745","https://access.redhat.com/errata/RHSA-2026:10774","https://access.redhat.com/errata/RHSA-2026:10949","https://access.redhat.com/errata/RHSA-2026:10950","https://access.redhat.com/errata/RHSA-2026:11062","https://access.redhat.com/errata/RHSA-2026:11077","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:13692","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14652","https://access.redhat.com/errata/RHSA-2026:14653","https://access.redhat.com/errata/RHSA-2026:14656","https://access.redhat.com/errata/RHSA-2026:16699","https://access.redhat.com/errata/RHSA-2026:17525","https://access.redhat.com/errata/RHSA-2026:17619","https://access.redhat.com/errata/RHSA-2026:19019","https://access.redhat.com/errata/RHSA-2026:19064","https://access.redhat.com/errata/RHSA-2026:19175","https://access.redhat.com/errata/RHSA-2026:19176","https://access.redhat.com/errata/RHSA-2026:19177","https://access.redhat.com/errata/RHSA-2026:19216","https://access.redhat.com/errata/RHSA-2026:19549","https://access.redhat.com/errata/RHSA-2026:19570","https://access.redhat.com/errata/RHSA-2026:19571","https://access.redhat.com/errata/RHSA-2026:19576","https://access.redhat.com/errata/RHSA-2026:19590","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:21682","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:26187","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:52400","https://access.redhat.com/errata/RHSA-2026:8822","https://access.redhat.com/errata/RHSA-2026:8824","https://access.redhat.com/errata/RHSA-2026:9228","https://access.redhat.com/security/cve/CVE-2026-6100","https://bugzilla.redhat.com/show_bug.cgi?id=2457932","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6100","description":"Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.\n\nThe vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.14"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-4603","versionConstraint":">= 3.0.0, < 3.0.14||>= 3.1.0, < 3.1.6||>= 3.2.0, < 3.2.2||>= 3.3.0, < 3.3.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-4603","fix":{"state":"fixed","versions":["3.0.14","3.1.6","3.2.2","3.3.1"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"3.0.14"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.6"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.2"},{"date":"2025-09-04","kind":"first-observed","version":"3.3.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-4603","cwe":"CWE-606","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2024-4603","cwe":"CWE-834","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-4603","date":"2026-10-08","epss":0.01131,"percentile":0.65415}],"risk":0.582465,"urls":["https://github.com/openssl/openssl/commit/3559e868e58005d15c6013a0c1fd832e51c73397","https://github.com/openssl/openssl/commit/53ea06486d296b890d565fb971b2764fcd826e7e","https://github.com/openssl/openssl/commit/9c39b3858091c152f52513c066ff2c5a47969f0d","https://github.com/openssl/openssl/commit/da343d0605c826ef197aceedc67e8e04f065f740","https://www.openssl.org/news/secadv/20240516.txt","http://www.openwall.com/lists/oss-security/2024/05/16/2","https://security.netapp.com/advisory/ntap-20240621-0001/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-4603","description":"Issue summary: Checking excessively long DSA keys or parameters may be very\nslow.\n\nImpact summary: Applications that use the functions EVP_PKEY_param_check()\nor EVP_PKEY_public_check() to check a DSA public key or DSA parameters may\nexperience long delays. Where the key or parameters that are being checked\nhave been obtained from an untrusted source this may lead to a Denial of\nService.\n\nThe functions EVP_PKEY_param_check() or EVP_PKEY_public_check() perform\nvarious checks on DSA parameters. Some of those computations take a long time\nif the modulus (`p` parameter) is too large.\n\nTrying to use a very large modulus is slow and OpenSSL will not allow using\npublic keys with a modulus which is over 10,000 bits in length for signature\nverification. However the key and parameter check functions do not limit\nthe modulus size when performing the checks.\n\nAn application that calls EVP_PKEY_param_check() or EVP_PKEY_public_check()\nand supplies a key or parameters obtained from an untrusted source could be\nvulnerable to a Denial of Service attack.\n\nThese functions are not called by OpenSSL itself on untrusted DSA keys so\nonly applications that directly call these functions may be vulnerable.\n\nAlso vulnerable are the OpenSSL pkey and pkeyparam command line applications\nwhen using the `-check` option.\n\nThe OpenSSL SSL/TLS implementation is not affected by this issue.\n\nThe OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-12718","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-12718","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":5.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12718","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2024-12718","date":"2026-10-08","epss":0.00768,"percentile":0.54191}],"risk":0.57984,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-12718","description":"A flaw was found in CPython's tarfile module. This vulnerability allows modification of file metadata, such as timestamps or permissions, outside the intended extraction directory via maliciously crafted tar archives using the filter=\"data\" or filter=\"tar\" extraction filters."},"relatedVulnerabilities":[{"id":"CVE-2024-12718","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12718","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2024-12718","date":"2026-10-08","epss":0.00768,"percentile":0.54191}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/127987","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-12718","description":"Allows modifying some file metadata (e.g. last modified) with filter=\"data\" or file permissions (chmod) with filter=\"tar\" of files outside the extraction directory.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-12718","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-12718","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":5.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12718","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2024-12718","date":"2026-10-08","epss":0.00768,"percentile":0.54191}],"risk":0.57984,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-12718","description":"A flaw was found in CPython's tarfile module. This vulnerability allows modification of file metadata, such as timestamps or permissions, outside the intended extraction directory via maliciously crafted tar archives using the filter=\"data\" or filter=\"tar\" extraction filters."},"relatedVulnerabilities":[{"id":"CVE-2024-12718","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12718","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2024-12718","date":"2026-10-08","epss":0.00768,"percentile":0.54191}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/127987","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-12718","description":"Allows modifying some file metadata (e.g. last modified) with filter=\"data\" or file permissions (chmod) with filter=\"tar\" of files outside the extraction directory.\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4330","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4330","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"risk":0.577485,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4330","description":"A flaw was found in CPython's tarfile module. This vulnerability allows bypassing of extraction filters, enabling symlink traversal outside the intended extraction directory and potential modification of file metadata via malicious tar archives using TarFile.extractall() or TarFile.extract() with the filter=\"data\" or filter=\"tar\" parameters. This issue leads to potentially overwriting or modifying system files and metadata."},"relatedVulnerabilities":[{"id":"CVE-2025-4330","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4330","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4330","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4330","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"risk":0.577485,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4330","description":"A flaw was found in CPython's tarfile module. This vulnerability allows bypassing of extraction filters, enabling symlink traversal outside the intended extraction directory and potential modification of file metadata via malicious tar archives using TarFile.extractall() or TarFile.extract() with the filter=\"data\" or filter=\"tar\" parameters. This issue leads to potentially overwriting or modifying system files and metadata."},"relatedVulnerabilities":[{"id":"CVE-2025-4330","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4330","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-4330","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4330","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"risk":0.577485,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4330","description":"A flaw was found in CPython's tarfile module. This vulnerability allows bypassing of extraction filters, enabling symlink traversal outside the intended extraction directory and potential modification of file metadata via malicious tar archives using TarFile.extractall() or TarFile.extract() with the filter=\"data\" or filter=\"tar\" parameters. This issue leads to potentially overwriting or modifying system files and metadata."},"relatedVulnerabilities":[{"id":"CVE-2025-4330","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4330","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4330","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4330","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"risk":0.577485,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4330","description":"A flaw was found in CPython's tarfile module. This vulnerability allows bypassing of extraction filters, enabling symlink traversal outside the intended extraction directory and potential modification of file metadata via malicious tar archives using TarFile.extractall() or TarFile.extract() with the filter=\"data\" or filter=\"tar\" parameters. This issue leads to potentially overwriting or modifying system files and metadata."},"relatedVulnerabilities":[{"id":"CVE-2025-4330","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4330","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-4330","date":"2026-10-08","epss":0.00939,"percentile":0.59709}],"urls":["https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f","https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4330","description":"Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata.\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63072","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-63072","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"risk":0.5725,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-63072","description":"A flaw was found in OpenSSL. A crafted CMS (Cryptographic Message Syntax) message can cause an 8-byte out-of-bounds heap write when it is decrypted with CMS_decrypt(). This issue occurs because the CMS decryption process incorrectly sizes the key-unwrap output buffer when using the AES-WRAP-PAD unwrap primitive. This can lead to memory corruption, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-63072","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63072","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63072","date":"2026-10-08","epss":0.00916,"percentile":0.58982}],"urls":["https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756","https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42","https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335","https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63072","description":"Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."}]},{"artifact":{"id":"0d66728c938c60a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.8.0.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vqf4-7m7x-wgfc","versionConstraint":"<1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vqf4-7m7x-wgfc","fix":{"state":"fixed","versions":["1.8.1"],"available":[{"date":"2025-12-04","kind":"first-observed","version":"1.8.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12183","cwe":"CWE-125","type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11"}],"epss":[{"cve":"CVE-2025-12183","date":"2026-10-08","epss":0.00697,"percentile":0.51565}],"risk":0.5680550000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-12183","https://github.com/yawkat/lz4-java/releases/tag/v1.8.1","https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-12183","https://www.sonatype.com/security-advisories/cve-2025-12183","http://www.openwall.com/lists/oss-security/2025/12/01/5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vqf4-7m7x-wgfc","description":"LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS"},"relatedVulnerabilities":[{"id":"CVE-2025-12183","cvss":[{"type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12183","cwe":"CWE-125","type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11"}],"epss":[{"cve":"CVE-2025-12183","date":"2026-10-08","epss":0.00697,"percentile":0.51565}],"urls":["https://github.com/yawkat/lz4-java/releases/tag/v1.8.1","https://www.sonatype.com/security-advisories/cve-2025-12183","http://www.openwall.com/lists/oss-security/2025/12/01/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12183","description":"Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input."}]},{"artifact":{"id":"1b7de6f060208fa3","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.8.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vqf4-7m7x-wgfc","versionConstraint":"<1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vqf4-7m7x-wgfc","fix":{"state":"fixed","versions":["1.8.1"],"available":[{"date":"2025-12-04","kind":"first-observed","version":"1.8.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12183","cwe":"CWE-125","type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11"}],"epss":[{"cve":"CVE-2025-12183","date":"2026-10-08","epss":0.00697,"percentile":0.51565}],"risk":0.5680550000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-12183","https://github.com/yawkat/lz4-java/releases/tag/v1.8.1","https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-12183","https://www.sonatype.com/security-advisories/cve-2025-12183","http://www.openwall.com/lists/oss-security/2025/12/01/5"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vqf4-7m7x-wgfc","description":"LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS"},"relatedVulnerabilities":[{"id":"CVE-2025-12183","cvss":[{"type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12183","cwe":"CWE-125","type":"Secondary","source":"103e4ec9-0a87-450b-af77-479448ddef11"}],"epss":[{"cve":"CVE-2025-12183","date":"2026-10-08","epss":0.00697,"percentile":0.51565}],"urls":["https://github.com/yawkat/lz4-java/releases/tag/v1.8.1","https://www.sonatype.com/security-advisories/cve-2025-12183","http://www.openwall.com/lists/oss-security/2025/12/01/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12183","description":"Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input."}]},{"artifact":{"id":"690a68ab4ef32559","cpes":["cpe:2.3:a:python:urllib3:2.4.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.4.0","type":"python","version":"2.4.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.6.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2xpw-w6gg-jr37","versionConstraint":">=1.0,<2.6.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.4.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-2xpw-w6gg-jr37","fix":{"state":"fixed","versions":["2.6.0"],"available":[{"date":"2025-12-06","kind":"first-observed","version":"2.6.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66471","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66471","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"risk":0.55924,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37","https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7","https://nvd.nist.gov/vuln/detail/CVE-2025-66471","https://github.com/urllib3/urllib3/commit/d0fde3672e4a4093f7587858dccfc298eb66e46c","https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2026-1994.yaml","https://github.com/urllib3/urllib3","https://pypi.org/project/urllib3"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2xpw-w6gg-jr37","description":"urllib3 streaming API improperly handles highly compressed data"},"relatedVulnerabilities":[{"id":"CVE-2025-66471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66471","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66471","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"urls":["https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7","https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data."}]},{"artifact":{"id":"690a68ab4ef32559","cpes":["cpe:2.3:a:python:urllib3:2.4.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.4.0","type":"python","version":"2.4.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.6.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gm62-xv2j-4w53","versionConstraint":">=1.24,<2.6.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.4.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-gm62-xv2j-4w53","fix":{"state":"fixed","versions":["2.6.0"],"available":[{"date":"2025-12-06","kind":"first-observed","version":"2.6.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66418","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66418","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"risk":0.55924,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53","https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8","https://nvd.nist.gov/vuln/detail/CVE-2025-66418"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gm62-xv2j-4w53","description":"urllib3 allows an unbounded number of links in the decompression chain"},"relatedVulnerabilities":[{"id":"CVE-2025-66418","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66418","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66418","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"urls":["https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8","https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0."}]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-4.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"< 0:2.5.0-4.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"fixed","versions":["0:2.5.0-4.el8_10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"0:2.5.0-4.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"risk":0.5565,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:72448","link":"https://access.redhat.com/errata/RHSA-2026:72448"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-66046","description":"A flaw was found in the Expat XML parsing library. A remote, unauthenticated attacker can supply a specially crafted XML document to trigger quadratic algorithmic complexity in the storeAtts() function, causing excessive CPU consumption and a denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-08","epss":0.00742,"percentile":0.53269}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-78.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"< 0:3.6.8-78.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"fixed","versions":["0:3.6.8-78.el8_10"],"available":[{"date":"2026-08-19","kind":"first-observed","version":"0:3.6.8-78.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.5549999999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:56219","link":"https://access.redhat.com/errata/RHSA-2026:56219"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11940","description":"A flaw was found in the `tarfile.extractall()` function within Python. A remote attacker could exploit this vulnerability by providing a specially crafted archive. This archive could bypass security filters by using a hardlink that references a symlink, allowing the symlink to be recreated outside the intended destination directory. This could lead to out-of-destination file reads or writes, potentially resulting in information disclosure or arbitrary file modification."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-78.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"< 0:3.6.8-78.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"fixed","versions":["0:3.6.8-78.el8_10"],"available":[{"date":"2026-08-19","kind":"first-observed","version":"0:3.6.8-78.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.5549999999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:56219","link":"https://access.redhat.com/errata/RHSA-2026:56219"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11940","description":"A flaw was found in the `tarfile.extractall()` function within Python. A remote attacker could exploit this vulnerability by providing a specially crafted archive. This archive could bypass security filters by using a hardlink that references a symlink, allowing the symlink to be recreated outside the intended destination directory. This could lead to out-of-destination file reads or writes, potentially resulting in information disclosure or arbitrary file modification."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.5549999999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11940","description":"A flaw was found in the `tarfile.extractall()` function within Python. A remote attacker could exploit this vulnerability by providing a specially crafted archive. This archive could bypass security filters by using a hardlink that references a symlink, allowing the symlink to be recreated outside the intended destination directory. This could lead to out-of-destination file reads or writes, potentially resulting in information disclosure or arbitrary file modification."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.3,"impactScore":5.2,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.5549999999999999,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11940","description":"A flaw was found in the `tarfile.extractall()` function within Python. A remote attacker could exploit this vulnerability by providing a specially crafted archive. This archive could bypass security filters by using a hardlink that references a symlink, allowing the symlink to be recreated outside the intended destination directory. This could lead to out-of-destination file reads or writes, potentially resulting in information disclosure or arbitrary file modification."},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7383","versionConstraint":">= 1.0.2, < 1.0.2zq||>= 1.1.1, < 1.1.1zh||>= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7383","fix":{"state":"fixed","versions":["1.0.2zq","1.1.1zh","3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"1.0.2zq"},{"date":"2026-06-11","kind":"first-observed","version":"1.1.1zh"},{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"risk":0.54678,"urls":["https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6","https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74","https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974","https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083","https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"1d1d40d939f8dea2","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"30ebb05b6b0fb071dbfcf713017c4a767a97bb9b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.135.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c653-97m9-rcg9","versionConstraint":"<=4.1.134.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c653-97m9-rcg9","fix":{"state":"fixed","versions":["4.1.135.Final"],"available":[{"date":"2026-06-16","kind":"first-observed","version":"4.1.135.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-50010","date":"2026-10-08","epss":0.00721,"percentile":0.52529}],"risk":0.54075,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://nvd.nist.gov/vuln/detail/CVE-2026-50010","https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c653-97m9-rcg9","description":"Netty: Wrapping plain trust manager silently disables hostname verification"},"relatedVulnerabilities":[{"id":"CVE-2026-50010","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-50010","cwe":"CWE-347","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-50010","date":"2026-10-08","epss":0.00721,"percentile":0.52529}],"urls":["https://github.com/netty/netty/releases/tag/netty-4.1.135.Final","https://github.com/netty/netty/releases/tag/netty-4.2.15.Final","https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9","https://access.redhat.com/errata/RHSA-2026:26017","https://access.redhat.com/errata/RHSA-2026:26018","https://access.redhat.com/errata/RHSA-2026:26586","https://access.redhat.com/errata/RHSA-2026:28573","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:37390","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49700","https://access.redhat.com/errata/RHSA-2026:49701","https://access.redhat.com/errata/RHSA-2026:50085","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-50010","https://bugzilla.redhat.com/show_bug.cgi?id=2488429","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50010","description":"Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0990","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0990","date":"2026-10-08","epss":0.00969,"percentile":0.60707}],"risk":0.528105,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0990","description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications."},"relatedVulnerabilities":[{"id":"CVE-2026-0990","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0990","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0990","date":"2026-10-08","epss":0.00969,"percentile":0.60707}],"urls":["https://access.redhat.com/errata/RHSA-2026:7519","https://access.redhat.com/security/cve/CVE-2026-0990","https://bugzilla.redhat.com/show_bug.cgi?id=2429959","https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0990","description":"A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recursion and call stack exhaustion. This ultimately results in a segmentation fault, causing a Denial of Service (DoS) by crashing affected applications."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-45445","versionConstraint":">= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-45445","fix":{"state":"fixed","versions":["3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45445","cwe":"CWE-325","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-45445","date":"2026-10-08","epss":0.00704,"percentile":0.51865}],"risk":0.528,"urls":["https://github.com/openssl/openssl/commit/323f0b6e7d530a4cb4336d50c88cb70f3ac2a451","https://github.com/openssl/openssl/commit/787a6dfba81b7b09c1e05ab31396c0cd7c36b3f7","https://github.com/openssl/openssl/commit/7ac4715234ee72d9f3c93426a2c08554b5b771af","https://github.com/openssl/openssl/commit/843c9b94ca9c2ed248bb30127bb4f3d7af0d607c","https://github.com/openssl/openssl/commit/983d54b5cce8d16147548ed1a37892d1720bbab6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45445","description":"Issue summary: When an application drives an AES-OCB context through the\npublic EVP_Cipher() one-shot interface, the application-supplied\ninitialisation vector (IV) is silently discarded.\n\nImpact summary: Every message encrypted under the same key uses the\nsame effective nonce regardless of the IV supplied by the caller,\nresulting in (key, nonce) reuse and loss of confidentiality.  If the\nsame code path is used to compute the authentication tag, the tag\ndepends only on the (key, IV) pair and not on the plaintext or\nciphertext, allowing universal forgery of arbitrary ciphertext from a\nsingle captured message.\n\nOpenSSL provides two ways to drive a cipher: the documented streaming\ninterface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level\none-shot, EVP_Cipher(), whose documentation explicitly recommends\nagainst use by applications in favour of EVP_CipherUpdate() and\nEVP_CipherFinal_ex().  The OCB provider's streaming handler flushes\nthe application-supplied IV into the OCB context before processing\ndata; the one-shot handler did not.  Every call to EVP_Cipher() on an\nAES-OCB context therefore ran with the all-zero key-derived offset\nstate left by cipher initialisation, regardless of the caller's IV.\n\nIf EVP_EncryptFinal_ex() is subsequently used to obtain the\nauthentication tag, the deferred IV setup runs at that point and\nclears the running checksum that should have been accumulated over the\nplaintext.  The resulting tag is a function of (key, IV) only and\nverifies against any ciphertext produced under the same (key, IV)\npair.\n\nThe OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a\nTLS cipher suite, and libssl does not call EVP_Cipher() in any case.\nApplications that drive AES-OCB through the documented streaming AEAD\nAPI (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected.  Only\napplications that combine the AES-OCB cipher with the EVP_Cipher()\none-shot API are vulnerable.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as AES-OCB is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34180","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-34180","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"risk":0.5244000000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-34180","description":"A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-34180","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34180","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-34180","date":"2026-10-08","epss":0.01311,"percentile":0.69792}],"urls":["https://github.com/openssl/openssl/commit/1c6908e4fa5fa568752221d8eaf561a809751e5d","https://github.com/openssl/openssl/commit/cbe418ae978539cf14a398a207dba834c0e93e83","https://github.com/openssl/openssl/commit/d93853c42110d6319e3df07842b488cb9f7ac5ff","https://github.com/openssl/openssl/commit/da5d62af75f69d6fbf7803743d7c56ac75461e43","https://github.com/openssl/openssl/commit/f696c73c3e61b8c502d040af62e690c060908a16","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34180","description":"Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive\nelement whose content exceeds 2 gigabytes in length may cause a heap buffer\nover-read on 64-bit Unix and Unix-like platforms.\n\nImpact summary: The heap buffer over-read may crash the application (Denial of\nService) or to load into the decoded ASN.1 object contents of memory beyond the\nend of the input buffer.  More typically such ASN.1 elements would instead be\ntruncated.\n\nAn integer truncation in OpenSSL's ASN.1 decoder causes the content length of\nan ASN.1 primitive element to be mishandled when it exceeds 2 gigabytes. In the\nworst case the truncated length is treated as a request to scan the binary\ncontent for a terminating zero byte, possibly causing OpenSSL to read either\nless than or beyond the end of the allocated buffer.\n\nApplications that pass attacker-supplied data to d2i_X509(), d2i_PKCS7(), or\nany other d2i_* decoding function are affected. OpenSSL's own command-line\ntools are not vulnerable, as data read through the BIO layer is checked before\nit reaches the affected code. The issue only affects 64-bit Unix and Unix-like\nplatforms; 32-bit platforms and 64-bit Windows are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3dd1075e2b063a17","cpes":["cpe:2.3:a:libtasn1:libtasn1:4.13-5.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libtasn1:4.13-5.el8_10:*:*:*:*:*:*:*"],"name":"libtasn1","purl":"pkg:rpm/redhat/libtasn1@4.13-5.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libtasn1-4.13-5.el8_10.src.rpm","type":"rpm","version":"4.13-5.el8_10","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:4.13-6.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-13151","versionConstraint":"< 0:4.13-6.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libtasn1","version":"0:4.13-5.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-13151","fix":{"state":"fixed","versions":["0:4.13-6.el8_10"],"available":[{"date":"2026-07-09","kind":"first-observed","version":"0:4.13-6.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"risk":0.5228750000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:36728","link":"https://access.redhat.com/errata/RHSA-2026:36728"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13151","description":"A flaw was found in libtasn1. A remote attacker could exploit a stack-based buffer overflow vulnerability in the `asn1_expend_octet_string` function. This occurs due to a failure in validating the size of input data. Successful exploitation can lead to a Denial of Service (DoS) condition, making the affected system or application unavailable."},"relatedVulnerabilities":[{"id":"CVE-2025-13151","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13151","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-13151","date":"2026-10-08","epss":0.01175,"percentile":0.66615}],"urls":["https://gitlab.com/gnutls/libtasn1","https://gitlab.com/gnutls/libtasn1/-/merge_requests/121","http://www.openwall.com/lists/oss-security/2026/01/08/5","https://www.kb.cert.org/vuls/id/271649"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13151","description":"Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string."}]},{"artifact":{"id":"7b479e2b1ed0e25e","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.34-5.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=libpng-1.6.34-5.el8.src.rpm","type":"rpm","version":"2:1.6.34-5.el8","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.34-10.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-25646","versionConstraint":"< 2:1.6.34-10.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libpng","version":"2:1.6.34-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-25646","fix":{"state":"fixed","versions":["2:1.6.34-10.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"2:1.6.34-10.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25646","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25646","cwe":"CWE-126","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25646","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25646","date":"2026-10-08","epss":0.00718,"percentile":0.52432}],"risk":0.52055,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4728","link":"https://access.redhat.com/errata/RHSA-2026:4728"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-25646","description":"A heap based buffer overflow flaw has been discovered in LibPNG. Prior to version 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification."},"relatedVulnerabilities":[{"id":"CVE-2026-25646","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25646","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25646","cwe":"CWE-126","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-25646","cwe":"CWE-125","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25646","date":"2026-10-08","epss":0.00718,"percentile":0.52432}],"urls":["https://github.com/pnggroup/libpng/commit/01d03b8453eb30ade759cd45c707e5a1c7277d88","https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3","http://www.openwall.com/lists/oss-security/2026/02/09/7","https://access.redhat.com/errata/RHSA-2026:10097","https://access.redhat.com/errata/RHSA-2026:12274","https://access.redhat.com/errata/RHSA-2026:14773","https://access.redhat.com/errata/RHSA-2026:15087","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:17596","https://access.redhat.com/errata/RHSA-2026:3031","https://access.redhat.com/errata/RHSA-2026:3405","https://access.redhat.com/errata/RHSA-2026:3551","https://access.redhat.com/errata/RHSA-2026:3573","https://access.redhat.com/errata/RHSA-2026:3574","https://access.redhat.com/errata/RHSA-2026:3575","https://access.redhat.com/errata/RHSA-2026:3576","https://access.redhat.com/errata/RHSA-2026:3577","https://access.redhat.com/errata/RHSA-2026:3968","https://access.redhat.com/errata/RHSA-2026:3969","https://access.redhat.com/errata/RHSA-2026:4221","https://access.redhat.com/errata/RHSA-2026:4222","https://access.redhat.com/errata/RHSA-2026:4306","https://access.redhat.com/errata/RHSA-2026:4501","https://access.redhat.com/errata/RHSA-2026:4728","https://access.redhat.com/errata/RHSA-2026:4729","https://access.redhat.com/errata/RHSA-2026:4730","https://access.redhat.com/errata/RHSA-2026:4731","https://access.redhat.com/errata/RHSA-2026:4732","https://access.redhat.com/errata/RHSA-2026:4756","https://access.redhat.com/errata/RHSA-2026:5606","https://access.redhat.com/errata/RHSA-2026:6439","https://access.redhat.com/errata/RHSA-2026:6445","https://access.redhat.com/errata/RHSA-2026:6466","https://access.redhat.com/errata/RHSA-2026:6467","https://access.redhat.com/errata/RHSA-2026:6468","https://access.redhat.com/errata/RHSA-2026:6469","https://access.redhat.com/errata/RHSA-2026:6553","https://access.redhat.com/errata/RHSA-2026:6732","https://access.redhat.com/errata/RHSA-2026:7032","https://access.redhat.com/errata/RHSA-2026:7033","https://access.redhat.com/errata/RHSA-2026:7034","https://access.redhat.com/errata/RHSA-2026:7035","https://access.redhat.com/errata/RHSA-2026:7036","https://access.redhat.com/errata/RHSA-2026:7239","https://access.redhat.com/errata/RHSA-2026:7243","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/security/cve/CVE-2026-25646","https://bugzilla.redhat.com/show_bug.cgi?id=2438542","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25646.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25646","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3833","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3833","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3833","date":"2026-10-08","epss":0.00892,"percentile":0.58203}],"risk":0.5129,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3833","description":"A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-3833","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3833","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3833","date":"2026-10-08","epss":0.00892,"percentile":0.58203}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:57402","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:62409","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:67857","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-3833","https://bugzilla.redhat.com/show_bug.cgi?id=2445763","https://gitlab.com/gnutls/gnutls/-/issues/1803"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3833","description":"A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure."}]},{"artifact":{"id":"4d6ef49515872d8c","cpes":["cpe:2.3:a:org.eclipse.jetty.security:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.security:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.security:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.security:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:security:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:security:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-security:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_security:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:security:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:security:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:security:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*"],"name":"jetty-security","purl":"pkg:maven/org.eclipse.jetty/jetty-security@9.4.57.v20241219","type":"java-archive","version":"9.4.57.v20241219","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0, https://www.eclipse.org/org/documents/epl-v10.php"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/usr/share/java/kafka/jetty-security-9.4.57.v20241219.jar","manifestName":"","pomArtifactID":"jetty-security","archiveDigests":[{"value":"2b545f68d45b947fdc6e279a0e8ae3630ec10e05","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jetty-security-9.4.57.v20241219.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jetty-security-9.4.57.v20241219.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"9.4.63"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2fvj-hgj9-j2gr","versionConstraint":">=9.4.0.v20161208,<=9.4.58.v20250814 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-security","version":"9.4.57.v20241219"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-2fvj-hgj9-j2gr","fix":{"state":"fixed","versions":["9.4.63"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"9.4.63"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10050","cwe":"CWE-173","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-10050","cwe":"CWE-303","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-10050","date":"2026-10-08","epss":0.00632,"percentile":0.48697}],"risk":0.51192,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://github.com/jetty/jetty.project/issues/15136","https://github.com/jetty/jetty.project/pull/15160","https://github.com/jetty/jetty.project/pull/15183","https://github.com/jetty/jetty.project/commit/4bcdbc7db387ce9e20e2c7571a7250280466221d","https://github.com/jetty/jetty.project/commit/d0bb829ccecbf19e3ad3d32f2649b2800f01222d","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.36","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.10"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2fvj-hgj9-j2gr","description":"Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution"},"relatedVulnerabilities":[{"id":"CVE-2026-10050","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10050","cwe":"CWE-173","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-10050","cwe":"CWE-303","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-10050","date":"2026-10-08","epss":0.00632,"percentile":0.48697}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-2fvj-hgj9-j2gr","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/120"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10050","description":"In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes.\n\n\n\nThis was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons.\n\n\n\nIf the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`.\n\n\n\nAn attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters.\n\n\n\nRecent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords."}]},{"artifact":{"id":"63790bc19247ade6","cpes":["cpe:2.3:a:python:requests:2.32.3:*:*:*:*:*:*:*"],"name":"requests","purl":"pkg:pypi/requests@2.32.3","type":"python","version":"2.32.3","language":"python","licenses":["Apache-2.0"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/requests-2.32.3.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/requests-2.32.3.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/requests-2.32.3.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/requests-2.32.3.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/local/lib/python3.9/site-packages/requests-2.32.3.dist-info/top_level.txt","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/requests-2.32.3.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.32.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9hjg-9r4m-mvj7","versionConstraint":"<2.32.4 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"requests","version":"2.32.3"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-9hjg-9r4m-mvj7","fix":{"state":"fixed","versions":["2.32.4"],"available":[{"date":"2025-06-10","kind":"first-observed","version":"2.32.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-47081","cwe":"CWE-522","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-47081","date":"2026-10-08","epss":0.0098,"percentile":0.61064}],"risk":0.5047,"urls":["https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7","https://nvd.nist.gov/vuln/detail/CVE-2024-47081","https://github.com/psf/requests/pull/6965","https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef","https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env","https://seclists.org/fulldisclosure/2025/Jun/2","http://seclists.org/fulldisclosure/2025/Jun/2","http://www.openwall.com/lists/oss-security/2025/06/03/11","http://www.openwall.com/lists/oss-security/2025/06/03/9","http://www.openwall.com/lists/oss-security/2025/06/04/1","http://www.openwall.com/lists/oss-security/2025/06/04/6"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9hjg-9r4m-mvj7","description":"Requests vulnerable to .netrc credentials leak via malicious URLs"},"relatedVulnerabilities":[{"id":"CVE-2024-47081","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-47081","cwe":"CWE-522","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-47081","date":"2026-10-08","epss":0.0098,"percentile":0.61064}],"urls":["https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef","https://github.com/psf/requests/pull/6965","https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7","https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env","https://seclists.org/fulldisclosure/2025/Jun/2","http://seclists.org/fulldisclosure/2025/Jun/2","http://www.openwall.com/lists/oss-security/2025/06/03/11","http://www.openwall.com/lists/oss-security/2025/06/03/9","http://www.openwall.com/lists/oss-security/2025/06/04/1","http://www.openwall.com/lists/oss-security/2025/06/04/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47081","description":"Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to version 2.32.4 to receive a fix. For older versions of Requests, use of the .netrc file can be disabled with `trust_env=False` on one's Requests Session."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:1.1.1k-17.el8_6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28390","versionConstraint":"< 1:1.1.1k-17.el8_6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-28390","fix":{"state":"fixed","versions":["1:1.1.1k-17.el8_6"],"available":[{"date":"2026-07-13","kind":"first-observed","version":"1:1.1.1k-17.el8_6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"risk":0.503125,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:38503","link":"https://access.redhat.com/errata/RHSA-2026:38503"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28390","description":"A flaw was found in OpenSSL. A remote attacker could exploit this vulnerability by sending a specially crafted Cryptographic Message Syntax (CMS) EnvelopedData message. During the processing of a KeyTransportRecipientInfo with RSA-OAEP encryption, the system attempts to access an optional parameter field without first verifying its presence. This leads to a NULL pointer dereference, which can cause applications processing the attacker-controlled CMS data to crash, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-28390","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28390","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28390","date":"2026-10-08","epss":0.00805,"percentile":0.55424}],"urls":["https://github.com/openssl/openssl/commit/01194a8f1941115cd0383bfa91c736dd3993c8bc","https://github.com/openssl/openssl/commit/2e39b7a6993be445fddb9fbce316fa756e0397b6","https://github.com/openssl/openssl/commit/af2a5fecd3e71a29e7568f9c1453dec5cebbaff4","https://github.com/openssl/openssl/commit/ea7b4ea4f9f853521ba34830cbcadc970d2e0788","https://github.com/openssl/openssl/commit/fd2f1a6cf53b9ceeca723a001aa4b825d7c7ee75","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28390","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-72.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12084","versionConstraint":"< 0:3.6.8-72.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-12084","fix":{"state":"fixed","versions":["0:3.6.8-72.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-72.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12084","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12084","date":"2026-10-08","epss":0.00799,"percentile":0.55201}],"risk":0.499375,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:1631","link":"https://access.redhat.com/errata/RHSA-2026:1631"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-12084","description":"A flaw was found in cpython. This vulnerability allows impacted availability via a quadratic algorithm in `xml.dom.minidom` methods, such as `appendChild()`, when building excessively nested documents due to a dependency on `_clear_id_cache()`"},"relatedVulnerabilities":[{"id":"CVE-2025-12084","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12084","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12084","date":"2026-10-08","epss":0.00799,"percentile":0.55201}],"urls":["https://github.com/python/cpython/commit/027f21e417b26eed4505ac2db101a4352b7c51a0","https://github.com/python/cpython/commit/08d8e18ad81cd45bc4a27d6da478b51ea49486e4","https://github.com/python/cpython/commit/27648a1818749ef44c420afe6173af6868715437","https://github.com/python/cpython/commit/41f468786762348960486c166833a218a0a436af","https://github.com/python/cpython/commit/57937a8e5e293f0dcba5115f7b7a11b1e0c9a273","https://github.com/python/cpython/commit/8d2d7bb2e754f8649a68ce4116271a4932f76907","https://github.com/python/cpython/commit/9c9dda6625a2a90d2a06c657eee021d6be19842d","https://github.com/python/cpython/commit/a46c10ec9d4050ab67b8a932e0859a2ea60c3cb8","https://github.com/python/cpython/commit/a696ba8b4d42fd632afc9bc88ad830a2e4cceed8","https://github.com/python/cpython/commit/c97e87593063d84a2bd9fe7068b30eb44de23dc0","https://github.com/python/cpython/commit/ddcd2acd85d891a53e281c773b3093f9db953964","https://github.com/python/cpython/commit/e91c11449cad34bac3ea55ee09ca557691d92b53","https://github.com/python/cpython/issues/142145","https://github.com/python/cpython/pull/142146"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12084","description":"When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-72.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12084","versionConstraint":"< 0:3.6.8-72.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-12084","fix":{"state":"fixed","versions":["0:3.6.8-72.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-72.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12084","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12084","date":"2026-10-08","epss":0.00799,"percentile":0.55201}],"risk":0.499375,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:1631","link":"https://access.redhat.com/errata/RHSA-2026:1631"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-12084","description":"A flaw was found in cpython. This vulnerability allows impacted availability via a quadratic algorithm in `xml.dom.minidom` methods, such as `appendChild()`, when building excessively nested documents due to a dependency on `_clear_id_cache()`"},"relatedVulnerabilities":[{"id":"CVE-2025-12084","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12084","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12084","date":"2026-10-08","epss":0.00799,"percentile":0.55201}],"urls":["https://github.com/python/cpython/commit/027f21e417b26eed4505ac2db101a4352b7c51a0","https://github.com/python/cpython/commit/08d8e18ad81cd45bc4a27d6da478b51ea49486e4","https://github.com/python/cpython/commit/27648a1818749ef44c420afe6173af6868715437","https://github.com/python/cpython/commit/41f468786762348960486c166833a218a0a436af","https://github.com/python/cpython/commit/57937a8e5e293f0dcba5115f7b7a11b1e0c9a273","https://github.com/python/cpython/commit/8d2d7bb2e754f8649a68ce4116271a4932f76907","https://github.com/python/cpython/commit/9c9dda6625a2a90d2a06c657eee021d6be19842d","https://github.com/python/cpython/commit/a46c10ec9d4050ab67b8a932e0859a2ea60c3cb8","https://github.com/python/cpython/commit/a696ba8b4d42fd632afc9bc88ad830a2e4cceed8","https://github.com/python/cpython/commit/c97e87593063d84a2bd9fe7068b30eb44de23dc0","https://github.com/python/cpython/commit/ddcd2acd85d891a53e281c773b3093f9db953964","https://github.com/python/cpython/commit/e91c11449cad34bac3ea55ee09ca557691d92b53","https://github.com/python/cpython/issues/142145","https://github.com/python/cpython/pull/142146"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12084","description":"When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents."}]},{"artifact":{"id":"d140b593a09d339e","cpes":["cpe:2.3:a:jason_r__coombs_project:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombs_project:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombsproject:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombsproject:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco-context:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco-context:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco_context:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco_context:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombs_project:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombs_project:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombs:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombs:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombsproject:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombsproject:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco-context:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco-context:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_context:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_context:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_project:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_project:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco-context:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco-context:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco_context:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco_context:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaracoproject:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaracoproject:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombs:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jason_r__coombs:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco-context:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco-context:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_context:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_context:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_project:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco_project:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaracoproject:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaracoproject:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python-jaraco:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python-jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python_jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python_jaraco:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:jaraco:jaraco_context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python:jaraco-context:5.3.0:*:*:*:*:*:*:*","cpe:2.3:a:python:jaraco_context:5.3.0:*:*:*:*:*:*:*"],"name":"jaraco-context","purl":"pkg:pypi/jaraco-context@5.3.0","type":"python","version":"5.3.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/top_level.txt","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/jaraco.context-5.3.0.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.1.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-58pv-8j8x-9vj2","versionConstraint":">=5.2.0,<6.1.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"jaraco-context","version":"5.3.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-58pv-8j8x-9vj2","fix":{"state":"fixed","versions":["6.1.0"],"available":[{"date":"2026-01-14","kind":"first-observed","version":"6.1.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23949","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23949","date":"2026-10-08","epss":0.00618,"percentile":0.47985}],"risk":0.49748999999999993,"urls":["https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2","https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9","https://nvd.nist.gov/vuln/detail/CVE-2026-23949","https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91","https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-58pv-8j8x-9vj2","description":"jaraco.context Has a Path Traversal Vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2026-23949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23949","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23949","date":"2026-10-08","epss":0.00618,"percentile":0.47985}],"urls":["https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91","https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9","https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2","https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23949","description":"jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow attackers to extract files outside the intended extraction directory when malicious tar archives are processed. The strip_first_component filter splits the path on the first `/` and extracts the second component, while allowing `../` sequences. Paths like `dummy_dir/../../etc/passwd` become `../../etc/passwd`. Note that this suffers from a nested tarball attack as well with multi-level tar files such as `dummy_dir/inner.tar.gz`, where the inner.tar.gz includes a traversal `dummy_dir/../../config/.env` that also gets translated to `../../config/.env`. Version 6.1.0 contains a patch for the issue."}]},{"artifact":{"id":"aa3226a75e79956c","cpes":["cpe:2.3:a:org.codehaus.plexus:plexus-utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:org.codehaus.plexus:plexus_utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:org.codehaus.plexus:plexus:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus-utils:plexus-utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus-utils:plexus_utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus_utils:plexus-utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus_utils:plexus_utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:codehaus:plexus-utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:codehaus:plexus_utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus-utils:plexus:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus:plexus-utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus:plexus_utils:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus_utils:plexus:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:codehaus:plexus:3.5.1:*:*:*:*:*:*:*","cpe:2.3:a:plexus:plexus:3.5.1:*:*:*:*:*:*:*"],"name":"plexus-utils","purl":"pkg:maven/org.codehaus.plexus/plexus-utils@3.5.1","type":"java-archive","version":"3.5.1","language":"java","licenses":["Apache-2.0"],"metadata":{"pomGroupID":"org.codehaus.plexus","virtualPath":"/usr/share/java/kafka/plexus-utils-3.5.1.jar","manifestName":"","pomArtifactID":"plexus-utils","archiveDigests":[{"value":"c6bfb17c97ecc8863e88778ea301be742c62b06d","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/plexus-utils-3.5.1.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/plexus-utils-3.5.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6fmv-xxpf-w3cw","versionConstraint":"<3.6.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.codehaus.plexus:plexus-utils","version":"3.5.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6fmv-xxpf-w3cw","fix":{"state":"fixed","versions":["3.6.1"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"3.6.1"}]},"cvss":[],"cwes":[{"cve":"CVE-2025-67030","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-67030","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-67030","date":"2026-10-08","epss":0.00663,"percentile":0.50153}],"risk":0.49724999999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-67030","https://github.com/codehaus-plexus/plexus-utils/issues/294","https://github.com/codehaus-plexus/plexus-utils/pull/295","https://github.com/codehaus-plexus/plexus-utils/pull/296","https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642","https://gist.github.com/weaver4VD/3216dac645220f8c9b488362f61241ec","https://github.com/codehaus-plexus/plexus-utils/releases/tag/plexus-utils-4.0.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6fmv-xxpf-w3cw","description":"Plexus-Utils has a Directory Traversal vulnerability in its extractFile method"},"relatedVulnerabilities":[{"id":"CVE-2025-67030","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":8.3,"impactScore":3.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-67030","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2025-67030","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-67030","date":"2026-10-08","epss":0.00663,"percentile":0.50153}],"urls":["https://gist.github.com/weaver4VD/3216dac645220f8c9b488362f61241ec","https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642","https://github.com/codehaus-plexus/plexus-utils/issues/294","https://github.com/codehaus-plexus/plexus-utils/pull/295","https://github.com/codehaus-plexus/plexus-utils/pull/296","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:35990","https://access.redhat.com/errata/RHSA-2026:35991","https://access.redhat.com/errata/RHSA-2026:35992","https://access.redhat.com/errata/RHSA-2026:35996","https://access.redhat.com/errata/RHSA-2026:35997","https://access.redhat.com/errata/RHSA-2026:36012","https://access.redhat.com/errata/RHSA-2026:38500","https://access.redhat.com/errata/RHSA-2026:38514","https://access.redhat.com/errata/RHSA-2026:38796","https://access.redhat.com/errata/RHSA-2026:40841","https://access.redhat.com/errata/RHSA-2026:41948","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:7109","https://access.redhat.com/errata/RHSA-2026:7380","https://access.redhat.com/security/cve/CVE-2025-67030","https://bugzilla.redhat.com/show_bug.cgi?id=2451409","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-67030.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-67030","description":"Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code"}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-177.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58015","versionConstraint":"< 0:2.56.4-177.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58015","fix":{"state":"fixed","versions":["0:2.56.4-177.el8_10"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"0:2.56.4-177.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"risk":0.49486,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:61766","link":"https://access.redhat.com/errata/RHSA-2026:61766"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."},"relatedVulnerabilities":[{"id":"CVE-2026-58015","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-58015","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-58015","date":"2026-10-08","epss":0.00908,"percentile":0.58707}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58015","https://bugzilla.redhat.com/show_bug.cgi?id=2492256","https://gitlab.gnome.org/GNOME/glib/-/issues/3931"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58015","description":"A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-177.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58010","versionConstraint":"< 0:2.56.4-177.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58010","fix":{"state":"fixed","versions":["0:2.56.4-177.el8_10"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"0:2.56.4-177.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.49047499999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:61766","link":"https://access.redhat.com/errata/RHSA-2026:61766"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58010","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58010","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58010","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58010","https://bugzilla.redhat.com/show_bug.cgi?id=2492243","https://gitlab.gnome.org/GNOME/glib/-/issues/3915"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58010","description":"A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-177.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58012","versionConstraint":"< 0:2.56.4-177.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58012","fix":{"state":"fixed","versions":["0:2.56.4-177.el8_10"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"0:2.56.4-177.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.49047499999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:61766","link":"https://access.redhat.com/errata/RHSA-2026:61766"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58012","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58012","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58012","https://bugzilla.redhat.com/show_bug.cgi?id=2492247","https://gitlab.gnome.org/GNOME/glib/-/issues/3918"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58012","description":"A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-177.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58013","versionConstraint":"< 0:2.56.4-177.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58013","fix":{"state":"fixed","versions":["0:2.56.4-177.el8_10"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"0:2.56.4-177.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"risk":0.49047499999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:61766","link":"https://access.redhat.com/errata/RHSA-2026:61766"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58013","cwe":"CWE-126","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58013","date":"2026-10-08","epss":0.00853,"percentile":0.56982}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58013","https://bugzilla.redhat.com/show_bug.cgi?id=2492248","https://gitlab.gnome.org/GNOME/glib/-/issues/3925"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58013","description":"A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary."}]},{"artifact":{"id":"7a0e2caa95ccb2be","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:9.4.57.v20241219:*:*:*:*:*:*:*","cpe:2.3:a:http:http:9.4.57.v20241219:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@9.4.57.v20241219","type":"java-archive","version":"9.4.57.v20241219","language":"java","licenses":["http://www.apache.org/licenses/LICENSE-2.0, https://www.eclipse.org/org/documents/epl-v10.php"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/usr/share/java/kafka/jetty-http-9.4.57.v20241219.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"c7a3a9c599346708894cf355e03105937f45f427","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jetty-http-9.4.57.v20241219.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jetty-http-9.4.57.v20241219.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qh8g-58pp-2wxh","versionConstraint":">=7.0.0,<=12.0.11 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"9.4.57.v20241219"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qh8g-58pp-2wxh","fix":{"state":"fixed","versions":["12.0.12"],"available":[{"date":"2024-10-15","kind":"first-observed","version":"12.0.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6763","date":"2026-10-08","epss":0.00965,"percentile":0.60529}],"risk":0.48250000000000004,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://nvd.nist.gov/vuln/detail/CVE-2024-6763","https://github.com/jetty/jetty.project/pull/12012","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qh8g-58pp-2wxh","description":"Eclipse Jetty URI parsing of invalid authority"},"relatedVulnerabilities":[{"id":"CVE-2024-6763","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6763","date":"2026-10-08","epss":0.00965,"percentile":0.60529}],"urls":["https://github.com/jetty/jetty.project/pull/12012","https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6763","description":"Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-41996","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-41996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"risk":0.481935,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-41996","description":"A vulnerability was found in the Diffie-Hellman Ephemeral (DHE) Key Agreement Protocol, where a malicious client can exploit the server's public key validation process. By forcing the server to use DHE and validating the order of public keys, the client can trigger expensive server-side modular exponentiation calculations. This issue results in asymmetric resource consumption, potentially leading to a denial of service (DoS) attack by overwhelming the server with computationally intensive operations."},"relatedVulnerabilities":[{"id":"CVE-2024-41996","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-41996","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-41996","date":"2026-10-08","epss":0.01083,"percentile":0.6416}],"urls":["https://dheatattack.gitlab.io/details/","https://dheatattack.gitlab.io/faq/","https://gist.github.com/c0r0n3r/abccc14d4d96c0442f3a77fa5ca255d1","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-485750.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-41996","description":"Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key."}]},{"artifact":{"id":"5dd5ead7aa827e89","cpes":["cpe:2.3:a:apache:zookeeper:3.8.4:*:*:*:*:*:*:*"],"name":"zookeeper","purl":"pkg:maven/org.apache.zookeeper/zookeeper@3.8.4","type":"java-archive","version":"3.8.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.zookeeper","virtualPath":"/usr/share/java/cp-base-new/zookeeper-3.8.4.jar","manifestName":"","pomArtifactID":"zookeeper","archiveDigests":[{"value":"6638e37b887b5a279044afbdc9928e19f678eb2e","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/zookeeper-3.8.4.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/zookeeper-3.8.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.8.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7xrh-hqfc-g7qr","versionConstraint":">=3.8.0,<3.8.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.zookeeper:zookeeper","version":"3.8.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7xrh-hqfc-g7qr","fix":{"state":"fixed","versions":["3.8.6"],"available":[{"date":"2026-03-11","kind":"first-observed","version":"3.8.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-350","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24281","date":"2026-10-08","epss":0.00645,"percentile":0.49317}],"risk":0.480525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-24281","https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2","https://github.com/apache/zookeeper/commit/66c4efecdda1302d9cfb3af9eedb122b74452bf3","https://issues.apache.org/jira/browse/ZOOKEEPER-4986","http://www.openwall.com/lists/oss-security/2026/03/07/4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7xrh-hqfc-g7qr","description":"Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager"},"relatedVulnerabilities":[{"id":"CVE-2026-24281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-350","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24281","date":"2026-10-08","epss":0.00645,"percentile":0.49317}],"urls":["https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2","http://www.openwall.com/lists/oss-security/2026/03/07/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-24281","https://bugzilla.redhat.com/show_bug.cgi?id=2445449","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24281.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24281","description":"Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols."}]},{"artifact":{"id":"b9af4561da4d9058","cpes":["cpe:2.3:a:apache:zookeeper:3.8.4:*:*:*:*:*:*:*"],"name":"zookeeper","purl":"pkg:maven/org.apache.zookeeper/zookeeper@3.8.4","type":"java-archive","version":"3.8.4","language":"java","licenses":[],"metadata":{"pomGroupID":"org.apache.zookeeper","virtualPath":"/usr/share/java/kafka/zookeeper-3.8.4.jar","manifestName":"","pomArtifactID":"zookeeper","archiveDigests":[{"value":"6638e37b887b5a279044afbdc9928e19f678eb2e","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/zookeeper-3.8.4.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/zookeeper-3.8.4.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.8.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7xrh-hqfc-g7qr","versionConstraint":">=3.8.0,<3.8.6 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.zookeeper:zookeeper","version":"3.8.4"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7xrh-hqfc-g7qr","fix":{"state":"fixed","versions":["3.8.6"],"available":[{"date":"2026-03-11","kind":"first-observed","version":"3.8.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-350","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24281","date":"2026-10-08","epss":0.00645,"percentile":0.49317}],"risk":0.480525,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-24281","https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2","https://github.com/apache/zookeeper/commit/66c4efecdda1302d9cfb3af9eedb122b74452bf3","https://issues.apache.org/jira/browse/ZOOKEEPER-4986","http://www.openwall.com/lists/oss-security/2026/03/07/4"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7xrh-hqfc-g7qr","description":"Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager"},"relatedVulnerabilities":[{"id":"CVE-2026-24281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-350","type":"Secondary","source":"security@apache.org"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24281","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24281","date":"2026-10-08","epss":0.00645,"percentile":0.49317}],"urls":["https://lists.apache.org/thread/088ddsbrzhd5lxzbqf5n24yg0mwh9jt2","http://www.openwall.com/lists/oss-security/2026/03/07/4","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:34608","https://access.redhat.com/errata/RHSA-2026:8509","https://access.redhat.com/security/cve/CVE-2026-24281","https://bugzilla.redhat.com/show_bug.cgi?id=2445449","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24281.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24281","description":"Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker must present a certificate which is trusted by ZKTrustManager which makes the attack vector harder to exploit. Users are recommended to upgrade to version 3.8.6 or 3.9.5, which fixes this issue by introducing a new configuration option to disable reverse DNS lookup in client and quorum protocols."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-32990","versionConstraint":"< 0:3.6.16-8.el8_10.4 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-32990","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.4"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.16-8.el8_10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32990","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32990","date":"2026-10-08","epss":0.00834,"percentile":0.56371}],"risk":0.4795499999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:17415","link":"https://access.redhat.com/errata/RHSA-2025:17415"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-32990","description":"A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system."},"relatedVulnerabilities":[{"id":"CVE-2025-32990","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32990","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-32990","date":"2026-10-08","epss":0.00834,"percentile":0.56371}],"urls":["https://access.redhat.com/errata/RHSA-2025:16115","https://access.redhat.com/errata/RHSA-2025:16116","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:17348","https://access.redhat.com/errata/RHSA-2025:17361","https://access.redhat.com/errata/RHSA-2025:17415","https://access.redhat.com/errata/RHSA-2025:19088","https://access.redhat.com/errata/RHSA-2025:22529","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/security/cve/CVE-2025-32990","https://bugzilla.redhat.com/show_bug.cgi?id=2359620","https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html","http://www.openwall.com/lists/oss-security/2025/07/11/3","https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32990","description":"A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL pointer write, resulting in memory corruption and a denial-of-service (DoS) that could potentially crash the system."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-77.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 0:3.6.8-77.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["0:3.6.8-77.el8_10"],"available":[{"date":"2026-07-15","kind":"first-observed","version":"0:3.6.8-77.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:39320","link":"https://access.redhat.com/errata/RHSA-2026:39320"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15308","description":"A flaw was found in Python. Its incremental HTML parser can be exploited by a remote attacker. By sending specially crafted, uncontrolled data with repeated, incomplete markup declarations, the attacker can cause the system to consume excessive central processing unit (CPU) resources. This leads to a denial of service, making the affected system unresponsive."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-77.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"< 0:3.6.8-77.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"fixed","versions":["0:3.6.8-77.el8_10"],"available":[{"date":"2026-07-15","kind":"first-observed","version":"0:3.6.8-77.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:39320","link":"https://access.redhat.com/errata/RHSA-2026:39320"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15308","description":"A flaw was found in Python. Its incremental HTML parser can be exploited by a remote attacker. By sending specially crafted, uncontrolled data with repeated, incomplete markup declarations, the attacker can cause the system to consume excessive central processing unit (CPU) resources. This leads to a denial of service, making the affected system unresponsive."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-08","epss":0.00637,"percentile":0.48908}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"0d66728c938c60a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.8.0.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cmp6-m4wj-q63q","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cmp6-m4wj-q63q","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66566","cwe":"CWE-201","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66566","date":"2026-10-08","epss":0.00605,"percentile":0.47338}],"risk":0.47492499999999993,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-cmp6-m4wj-q63q","https://nvd.nist.gov/vuln/detail/CVE-2025-66566","https://github.com/yawkat/lz4-java/commit/33d180cb70c4d93c80fb0dc3ab3002f457e93840"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cmp6-m4wj-q63q","description":"yawkat LZ4 Java has a possible information leak in Java safe decompressor"},"relatedVulnerabilities":[{"id":"CVE-2025-66566","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66566","cwe":"CWE-201","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66566","date":"2026-10-08","epss":0.00605,"percentile":0.47338}],"urls":["https://github.com/yawkat/lz4-java/commit/33d180cb70c4d93c80fb0dc3ab3002f457e93840","https://github.com/yawkat/lz4-java/security/advisories/GHSA-cmp6-m4wj-q63q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66566","description":"yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1."}]},{"artifact":{"id":"1b7de6f060208fa3","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cmp6-m4wj-q63q","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cmp6-m4wj-q63q","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66566","cwe":"CWE-201","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66566","date":"2026-10-08","epss":0.00605,"percentile":0.47338}],"risk":0.47492499999999993,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-cmp6-m4wj-q63q","https://nvd.nist.gov/vuln/detail/CVE-2025-66566","https://github.com/yawkat/lz4-java/commit/33d180cb70c4d93c80fb0dc3ab3002f457e93840"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cmp6-m4wj-q63q","description":"yawkat LZ4 Java has a possible information leak in Java safe decompressor"},"relatedVulnerabilities":[{"id":"CVE-2025-66566","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66566","cwe":"CWE-201","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66566","date":"2026-10-08","epss":0.00605,"percentile":0.47338}],"urls":["https://github.com/yawkat/lz4-java/commit/33d180cb70c4d93c80fb0dc3ab3002f457e93840","https://github.com/yawkat/lz4-java/security/advisories/GHSA-cmp6-m4wj-q63q"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66566","description":"yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42015","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42015","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42015","date":"2026-10-08","epss":0.0092,"percentile":0.59061}],"risk":0.4738,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42015","description":"A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts."},"relatedVulnerabilities":[{"id":"CVE-2026-42015","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42015","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42015","date":"2026-10-08","epss":0.0092,"percentile":0.59061}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42015","https://bugzilla.redhat.com/show_bug.cgi?id=2467678","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42015","description":"A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when appending to a bag that already contains 32 elements. This memory corruption could lead to a denial of service (DoS) or potentially other unspecified impacts."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-177.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58011","versionConstraint":"< 0:2.56.4-177.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58011","fix":{"state":"fixed","versions":["0:2.56.4-177.el8_10"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"0:2.56.4-177.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"risk":0.4692,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:61766","link":"https://access.redhat.com/errata/RHSA-2026:61766"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58011","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58011","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58011","date":"2026-10-08","epss":0.00816,"percentile":0.55788}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58011","https://bugzilla.redhat.com/show_bug.cgi?id=2492245","https://gitlab.gnome.org/GNOME/glib/-/issues/3917","https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58011","description":"A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-54874","versionConstraint":">= 1.0.2, < 1.0.2zr||>= 1.1.1, < 1.1.1zi||>= 3.0.0, < 3.0.22||>= 3.4.0, < 3.4.7||>= 3.5.0, < 3.5.8||>= 3.6.0, < 3.6.4||>= 4.0.0, < 4.0.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"fixed","versions":["1.0.2zr","1.1.1zi","3.0.22","3.4.7","3.5.8","3.6.4","4.0.2"],"available":[{"date":"2026-08-29","kind":"first-observed","version":"1.0.2zr"},{"date":"2026-08-29","kind":"first-observed","version":"1.1.1zi"},{"date":"2026-08-29","kind":"first-observed","version":"3.0.22"},{"date":"2026-08-29","kind":"first-observed","version":"3.4.7"},{"date":"2026-08-29","kind":"first-observed","version":"3.5.8"},{"date":"2026-08-29","kind":"first-observed","version":"3.6.4"},{"date":"2026-08-29","kind":"first-observed","version":"4.0.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.46649999999999997,"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"},"relatedVulnerabilities":[]},{"artifact":{"id":"3fa5e9a1b5f18fed","cpes":["cpe:2.3:a:redhat:pcre2:10.32-3.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.32-3.el8_6:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=rhel-8.10&upstream=pcre2-10.32-3.el8_6.src.rpm","type":"rpm","version":"10.32-3.el8_6","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-41409","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"pcre2","version":"0:10.32-3.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2022-41409","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"risk":0.465215,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-41409","description":"A flaw was found in PCRE2, where it is susceptible to an integer overflow vulnerability triggered by a negative repeat value in the pcre2test subject line that causes infinite looping. This flaw allows a remote attacker to pass specially crafted data to the application, initiating an integer overflow and executing a denial of service (DoS) attack."},"relatedVulnerabilities":[{"id":"CVE-2022-41409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-41409","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-41409","date":"2026-10-08","epss":0.01121,"percentile":0.65174}],"urls":["https://github.com/PCRE2Project/pcre2/commit/94e1c001761373b7d9450768aa15d04c25547a35","https://github.com/PCRE2Project/pcre2/issues/141"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-41409","description":"Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42766","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42766","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"risk":0.46065000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42766","description":"A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service."},"relatedVulnerabilities":[{"id":"CVE-2026-42766","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42766","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42766","date":"2026-10-08","epss":0.0111,"percentile":0.64898}],"urls":["https://github.com/openssl/openssl/commit/056d06c1918fafbb98c1c85a02e4c47cc4e199ce","https://github.com/openssl/openssl/commit/12bc26ffb3a2be728c9b86e1cae277de5b33dfa4","https://github.com/openssl/openssl/commit/3ff64913615d648cfbb6a6f1cf5529ae7ea829d7","https://github.com/openssl/openssl/commit/ab52d88cb5374876d59aee3c91f9e4ccce2b7ce4","https://github.com/openssl/openssl/commit/da26f368732b83e40e9d356fe61c3d3aaab6d2e8","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42766","description":"Issue summary: A specially crafted password-encrypted CMS message\ncan trigger a NULL pointer dereference during CMS decryption.\n\nImpact summary: This NULL pointer dereference leads to an application crash\nand a Denial of Service.\n\nThe CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined as\nOPTIONAL in the ASN.1 specification and may therefore be absent in specially\ncrafted inputs. During the password-based CMS decryption the OpenSSL\nCMS implementation dereferences this field without first checking whether it\nwas present.\n\nAn attacker who supplies such a CMS message to an application performing\npassword-based CMS decryption can trigger an application crash, leading to\na Denial of Service.\n\nApplications that process password-encrypted CMS messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.19"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-69419","versionConstraint":">= 1.1.1, < 1.1.1ze||>= 3.0.0, < 3.0.19||>= 3.3.0, < 3.3.6||>= 3.4.0, < 3.4.4||>= 3.5.0, < 3.5.5||>= 3.6.0, < 3.6.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-69419","fix":{"state":"fixed","versions":["1.1.1ze","3.0.19","3.3.6","3.4.4","3.5.5","3.6.1"],"available":[{"date":"2026-01-29","kind":"first-observed","version":"1.1.1ze"},{"date":"2026-01-29","kind":"first-observed","version":"3.0.19"},{"date":"2026-01-29","kind":"first-observed","version":"3.3.6"},{"date":"2026-01-29","kind":"first-observed","version":"3.4.4"},{"date":"2026-01-29","kind":"first-observed","version":"3.5.5"},{"date":"2026-01-29","kind":"first-observed","version":"3.6.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69419","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69419","date":"2026-10-08","epss":0.00616,"percentile":0.47921}],"risk":0.45892,"urls":["https://github.com/openssl/openssl/commit/41be0f216404f14457bbf3b9cc488dba60b49296","https://github.com/openssl/openssl/commit/7e9cac9832e4705b91987c2474ed06a37a93cecb","https://github.com/openssl/openssl/commit/a26a90d38edec3748566129d824e664b54bee2e2","https://github.com/openssl/openssl/commit/cda12de3bc0e333ea8d2c6fd15001dbdaf280015","https://github.com/openssl/openssl/commit/ff628933755075446bca8307e8417c14d164b535","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69419","description":"Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously\ncrafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing\nnon-ASCII BMP code point can trigger a one byte write before the allocated\nbuffer.\n\nImpact summary: The out-of-bounds write can cause a memory corruption\nwhich can have various consequences including a Denial of Service.\n\nThe OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12\nBMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,\nthe helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16\nsource byte count as the destination buffer capacity to UTF8_putc(). For BMP\ncode points above U+07FF, UTF-8 requires three bytes, but the forwarded\ncapacity can be just two bytes. UTF8_putc() then returns -1, and this negative\nvalue is added to the output length without validation, causing the\nlength to become negative. The subsequent trailing NUL byte is then written\nat a negative offset, causing write outside of heap allocated buffer.\n\nThe vulnerability is reachable via the public PKCS12_get_friendlyname() API\nwhen parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a\ndifferent code path that avoids this issue, PKCS12_get_friendlyname() directly\ninvokes the vulnerable function. Exploitation requires an attacker to provide\na malicious PKCS#12 file to be parsed by the application and the attacker\ncan just trigger a one zero byte write before the allocated buffer.\nFor that reason the issue was assessed as Low severity according to our\nSecurity Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69421","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-69421","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69421","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69421","date":"2026-10-08","epss":0.00958,"percentile":0.60302}],"risk":0.45505,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-69421","description":"A flaw was found in OpenSSL. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by providing a specially crafted, malformed PKCS#12 file to an application that processes it. The flaw occurs due to a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function when handling the malformed file, leading to an application crash."},"relatedVulnerabilities":[{"id":"CVE-2025-69421","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69421","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69421","date":"2026-10-08","epss":0.00958,"percentile":0.60302}],"urls":["https://github.com/openssl/openssl/commit/3524a29271f8191b8fd8a5257eb05173982a097b","https://github.com/openssl/openssl/commit/36ecb4960872a4ce04bf6f1e1f4e78d75ec0c0c7","https://github.com/openssl/openssl/commit/4bbc8d41a72c842ce4077a8a3eccd1109aaf74bd","https://github.com/openssl/openssl/commit/643986985cd1c21221f941129d76fe0c2785aeb3","https://github.com/openssl/openssl/commit/a2dbc539f0f9cc63832709fa5aa33ad9495eb19c","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69421","description":"Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."}]},{"artifact":{"id":"1435e8d59fac6b89","cpes":["cpe:2.3:a:redhat:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.30-9.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=tar-1.30-9.el8.src.rpm","type":"rpm","version":"2:1.30-9.el8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-20193","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"tar","version":"2:1.30-9.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2021-20193","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20193","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-20193","date":"2026-10-08","epss":0.01092,"percentile":0.64394}],"risk":0.4531799999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2021-20193","description":"A flaw was found in the src/list.c of tar. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability."},"relatedVulnerabilities":[{"id":"CVE-2021-20193","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2021-20193","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2021-20193","cwe":"CWE-401","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-20193","date":"2026-10-08","epss":0.01092,"percentile":0.64394}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1917565","https://git.savannah.gnu.org/cgit/tar.git/commit/?id=d9d4435692150fa8ff68e1b1a473d187cc3fd777","https://savannah.gnu.org/bugs/?59897","https://security.gentoo.org/glsa/202105-29"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-20193","description":"A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.45315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-50495","description":"A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-50495","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-50495","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"risk":0.45315,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-50495","description":"A vulnerability was found in the NCurses package, where a segmentation fault may be triggered through _nc_wrap_entry()."},"relatedVulnerabilities":[{"id":"CVE-2023-50495","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2023-50495","date":"2026-10-08","epss":0.00954,"percentile":0.60184}],"urls":["https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00020.html","https://lists.gnu.org/archive/html/bug-ncurses/2023-04/msg00029.html","https://security.netapp.com/advisory/ntap-20240119-0008/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LU4MYMKFEZQ5VSCVLRIZGDQOUW3T44GT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-50495","description":"NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry()."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-7774","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"risk":0.449075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7774","description":"A flaw was found in the `tarfile.data_filter` function within the Python `tarfile` module. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive containing malicious link entries, such as symlinks with empty or directory-like names. This bypass allows the attacker to redirect subsequent archive members outside the intended extraction directory, leading to arbitrary file writes on the system where the archive is extracted. The impact of this flaw is limited by the permissions of the extracting process."},"relatedVulnerabilities":[{"id":"CVE-2026-7774","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7774","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-7774","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"risk":0.449075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7774","description":"A flaw was found in the `tarfile.data_filter` function within the Python `tarfile` module. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive containing malicious link entries, such as symlinks with empty or directory-like names. This bypass allows the attacker to redirect subsequent archive members outside the intended extraction directory, leading to arbitrary file writes on the system where the archive is extracted. The impact of this flaw is limited by the permissions of the extracting process."},"relatedVulnerabilities":[{"id":"CVE-2026-7774","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7774","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7774","date":"2026-10-08","epss":0.00781,"percentile":0.54586}],"urls":["https://github.com/python/cpython/commit/0478bd83d82b255e0f29f613367a59d261e7eaa2","https://github.com/python/cpython/commit/0d28f5e46e151718972dfabd91205444d0037b6d","https://github.com/python/cpython/commit/10a13bee3c24f9c62b602e696334ff2272a40efc","https://github.com/python/cpython/commit/578411982c16f753f4893532510099ef665117da","https://github.com/python/cpython/commit/5cf47a248c35c375d610b87b2f72fd1ed454b558","https://github.com/python/cpython/commit/74cca9a92fb7d653e404843a56b8bdc7b0afdbbf","https://github.com/python/cpython/commit/c063191cb7f9170f9565e305f8aa2b79ab2bf609","https://github.com/python/cpython/issues/149486","https://github.com/python/cpython/pull/149487","https://mail.python.org/archives/list/security-announce@python.org/thread/4FU62L2M6RMMHT2QPGQNPEHHUND7CEX5/","http://www.openwall.com/lists/oss-security/2026/06/04/9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7774","description":"tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-177.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58014","versionConstraint":"< 0:2.56.4-177.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58014","fix":{"state":"fixed","versions":["0:2.56.4-177.el8_10"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"0:2.56.4-177.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"risk":0.4440299999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:61766","link":"https://access.redhat.com/errata/RHSA-2026:61766"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-58014","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":8.6,"impactScore":4.8,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58014","cwe":"CWE-193","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-58014","date":"2026-10-08","epss":0.00722,"percentile":0.52535}],"urls":["https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66357","https://access.redhat.com/errata/RHSA-2026:70586","https://access.redhat.com/errata/RHSA-2026:70646","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73851","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-58014","https://bugzilla.redhat.com/show_bug.cgi?id=2492255","https://gitlab.gnome.org/GNOME/glib/-/issues/3930"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58014","description":"A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-169.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-14087","versionConstraint":"< 0:2.56.4-169.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-14087","fix":{"state":"fixed","versions":["0:2.56.4-169.el8_10"],"available":[{"date":"2026-05-12","kind":"first-observed","version":"0:2.56.4-169.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14087","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14087","date":"2026-10-08","epss":0.00826,"percentile":0.56148}],"risk":0.43778,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:15953","link":"https://access.redhat.com/errata/RHSA-2026:15953"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14087","description":"A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings."},"relatedVulnerabilities":[{"id":"CVE-2025-14087","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14087","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14087","date":"2026-10-08","epss":0.00826,"percentile":0.56148}],"urls":["https://access.redhat.com/errata/RHSA-2026:15953","https://access.redhat.com/errata/RHSA-2026:15969","https://access.redhat.com/errata/RHSA-2026:15971","https://access.redhat.com/errata/RHSA-2026:19148","https://access.redhat.com/errata/RHSA-2026:19361","https://access.redhat.com/errata/RHSA-2026:19452","https://access.redhat.com/errata/RHSA-2026:19457","https://access.redhat.com/errata/RHSA-2026:19459","https://access.redhat.com/errata/RHSA-2026:19460","https://access.redhat.com/errata/RHSA-2026:19523","https://access.redhat.com/errata/RHSA-2026:19524","https://access.redhat.com/errata/RHSA-2026:19565","https://access.redhat.com/errata/RHSA-2026:19566","https://access.redhat.com/errata/RHSA-2026:19567","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:22634","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:49512","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2025-14087","https://bugzilla.redhat.com/show_bug.cgi?id=2419093","https://gitlab.gnome.org/GNOME/glib/-/issues/3834"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14087","description":"A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings."}]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.14.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.14.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9076","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-9076","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"risk":0.43298500000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-9076","description":"A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication."},"relatedVulnerabilities":[{"id":"CVE-2026-9076","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9076","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-9076","date":"2026-10-08","epss":0.00973,"percentile":0.60827}],"urls":["https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb","https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0","https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98","https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26","https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9076","description":"Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue."}]},{"artifact":{"id":"9cd3f9b2449b3e61","cpes":["cpe:2.3:a:krb5-libs:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5-libs:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*"],"name":"krb5-libs","purl":"pkg:rpm/redhat/krb5-libs@1.18.2-31.el8_10?arch=x86_64&distro=rhel-8.10&upstream=krb5-1.18.2-31.el8_10.src.rpm","type":"rpm","version":"1.18.2-31.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.18.2-31.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.18.2-34.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40355","versionConstraint":"< 0:1.18.2-34.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"krb5","version":"1.18.2-31.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"fixed","versions":["0:1.18.2-34.el8_10"],"available":[{"date":"2026-05-13","kind":"first-observed","version":"0:1.18.2-34.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-08","epss":0.00792,"percentile":0.54983}],"risk":0.4316400000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:16799","link":"https://access.redhat.com/errata/RHSA-2026:16799"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-40355","description":"A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-40355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-08","epss":0.00792,"percentile":0.54983}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."}]},{"artifact":{"id":"768c3e9322f3144c","cpes":["cpe:2.3:a:krb5-workstation:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5-workstation:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_workstation:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_workstation:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*"],"name":"krb5-workstation","purl":"pkg:rpm/redhat/krb5-workstation@1.18.2-31.el8_10?arch=x86_64&distro=rhel-8.10&upstream=krb5-1.18.2-31.el8_10.src.rpm","type":"rpm","version":"1.18.2-31.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.18.2-31.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.18.2-34.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40355","versionConstraint":"< 0:1.18.2-34.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"krb5","version":"1.18.2-31.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"fixed","versions":["0:1.18.2-34.el8_10"],"available":[{"date":"2026-05-13","kind":"first-observed","version":"0:1.18.2-34.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-08","epss":0.00792,"percentile":0.54983}],"risk":0.4316400000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:16799","link":"https://access.redhat.com/errata/RHSA-2026:16799"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-40355","description":"A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-40355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-08","epss":0.00792,"percentile":0.54983}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."}]},{"artifact":{"id":"89b077cce2783e5f","cpes":["cpe:2.3:a:libkadm5:libkadm5:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libkadm5:1.18.2-31.el8_10:*:*:*:*:*:*:*"],"name":"libkadm5","purl":"pkg:rpm/redhat/libkadm5@1.18.2-31.el8_10?arch=x86_64&distro=rhel-8.10&upstream=krb5-1.18.2-31.el8_10.src.rpm","type":"rpm","version":"1.18.2-31.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.18.2-31.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.18.2-34.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40355","versionConstraint":"< 0:1.18.2-34.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"krb5","version":"1.18.2-31.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-40355","fix":{"state":"fixed","versions":["0:1.18.2-34.el8_10"],"available":[{"date":"2026-05-13","kind":"first-observed","version":"0:1.18.2-34.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-08","epss":0.00792,"percentile":0.54983}],"risk":0.4316400000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:16799","link":"https://access.redhat.com/errata/RHSA-2026:16799"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-40355","description":"A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit a NULL pointer dereference vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the termination of the process, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-40355","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40355","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40355","date":"2026-10-08","epss":0.00792,"percentile":0.54983}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/","https://cert-portal.siemens.com/productcert/html/ssa-019113.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40355","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message."}]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.430965,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77214","description":"A flaw was found in expat. A remote attacker can exploit this vulnerability through repeated parse buffer operations with unvalidated buffer lengths, causing a heap buffer over-read. This issue primarily leads to information disclosure by leaking adjacent heap memory contents, which could assist in bypassing security mitigations such as Address Space Layout Randomization (ASLR), or result in a Denial of Service (DoS) by crashing the application."},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-45322","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-45322","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45322","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45322","date":"2026-10-08","epss":0.00965,"percentile":0.60527}],"risk":0.4294250000000001,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-45322","description":"A flaw was found in libxml2. In an out-of-memory condition or when limiting the memory allocation, processing a XML document using the HTML parser may result in a use-after-free vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2023-45322","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45322","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-45322","date":"2026-10-08","epss":0.00965,"percentile":0.60527}],"urls":["http://www.openwall.com/lists/oss-security/2023/10/06/5","https://gitlab.gnome.org/GNOME/libxml2/-/issues/344","https://gitlab.gnome.org/GNOME/libxml2/-/issues/583","https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45322","description":"libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is \"I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail.\""}]},{"artifact":{"id":"9cd3f9b2449b3e61","cpes":["cpe:2.3:a:krb5-libs:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5-libs:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_libs:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-libs:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_libs:1.18.2-31.el8_10:*:*:*:*:*:*:*"],"name":"krb5-libs","purl":"pkg:rpm/redhat/krb5-libs@1.18.2-31.el8_10?arch=x86_64&distro=rhel-8.10&upstream=krb5-1.18.2-31.el8_10.src.rpm","type":"rpm","version":"1.18.2-31.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.18.2-31.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.18.2-34.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40356","versionConstraint":"< 0:1.18.2-34.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"krb5","version":"1.18.2-31.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"fixed","versions":["0:1.18.2-34.el8_10"],"available":[{"date":"2026-05-13","kind":"first-observed","version":"0:1.18.2-34.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-08","epss":0.00783,"percentile":0.54659}],"risk":0.42673500000000003,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:16799","link":"https://access.redhat.com/errata/RHSA-2026:16799"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-40356","description":"A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-40356","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-08","epss":0.00783,"percentile":0.54659}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."}]},{"artifact":{"id":"768c3e9322f3144c","cpes":["cpe:2.3:a:krb5-workstation:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5-workstation:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_workstation:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5_workstation:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5-workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:krb5:krb5_workstation:1.18.2-31.el8_10:*:*:*:*:*:*:*"],"name":"krb5-workstation","purl":"pkg:rpm/redhat/krb5-workstation@1.18.2-31.el8_10?arch=x86_64&distro=rhel-8.10&upstream=krb5-1.18.2-31.el8_10.src.rpm","type":"rpm","version":"1.18.2-31.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.18.2-31.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.18.2-34.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40356","versionConstraint":"< 0:1.18.2-34.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"krb5","version":"1.18.2-31.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"fixed","versions":["0:1.18.2-34.el8_10"],"available":[{"date":"2026-05-13","kind":"first-observed","version":"0:1.18.2-34.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-08","epss":0.00783,"percentile":0.54659}],"risk":0.42673500000000003,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:16799","link":"https://access.redhat.com/errata/RHSA-2026:16799"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-40356","description":"A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-40356","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-08","epss":0.00783,"percentile":0.54659}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."}]},{"artifact":{"id":"89b077cce2783e5f","cpes":["cpe:2.3:a:libkadm5:libkadm5:1.18.2-31.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libkadm5:1.18.2-31.el8_10:*:*:*:*:*:*:*"],"name":"libkadm5","purl":"pkg:rpm/redhat/libkadm5@1.18.2-31.el8_10?arch=x86_64&distro=rhel-8.10&upstream=krb5-1.18.2-31.el8_10.src.rpm","type":"rpm","version":"1.18.2-31.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"krb5","version":"1.18.2-31.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.18.2-34.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40356","versionConstraint":"< 0:1.18.2-34.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"krb5","version":"1.18.2-31.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-40356","fix":{"state":"fixed","versions":["0:1.18.2-34.el8_10"],"available":[{"date":"2026-05-13","kind":"first-observed","version":"0:1.18.2-34.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-08","epss":0.00783,"percentile":0.54659}],"risk":0.42673500000000003,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:16799","link":"https://access.redhat.com/errata/RHSA-2026:16799"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-40356","description":"A flaw was found in MIT Kerberos 5 (krb5). An unauthenticated remote attacker can exploit an integer underflow and an out-of-bounds read vulnerability by calling `gss_accept_sec_context()` on a system with a NegoEx mechanism registered. This can lead to the process terminating, resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-40356","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40356","cwe":"CWE-191","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40356","date":"2026-10-08","epss":0.00783,"percentile":0.54659}],"urls":["https://cems.fun/2026/04/27/krb5-two-unauthenticated-network-vulnerabilities.html","https://github.com/krb5/krb5/commit/2e75f0d9362fb979f5fc92829431a590a130929f","https://web.mit.edu/kerberos/advisories/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40356","description":"In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message."}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-17.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59843","versionConstraint":"< 0:0.9.6-17.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-59843","fix":{"state":"fixed","versions":["0:0.9.6-17.el8_10"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0:0.9.6-17.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59843","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59843","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59843","date":"2026-10-08","epss":0.00725,"percentile":0.52664}],"risk":0.416875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:62218","link":"https://access.redhat.com/errata/RHSA-2026:62218"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59843","description":"A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-59843","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59843","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59843","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59843","date":"2026-10-08","epss":0.00725,"percentile":0.52664}],"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59843","https://bugzilla.redhat.com/show_bug.cgi?id=2498176"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59843","description":"A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-17.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59843","versionConstraint":"< 0:0.9.6-17.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-59843","fix":{"state":"fixed","versions":["0:0.9.6-17.el8_10"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0:0.9.6-17.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59843","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59843","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59843","date":"2026-10-08","epss":0.00725,"percentile":0.52664}],"risk":0.416875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:62218","link":"https://access.redhat.com/errata/RHSA-2026:62218"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59843","description":"A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-59843","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59843","cwe":"CWE-835","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-59843","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-59843","date":"2026-10-08","epss":0.00725,"percentile":0.52664}],"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59843","https://bugzilla.redhat.com/show_bug.cgi?id=2498176"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59843","description":"A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-71.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-8194","versionConstraint":"< 0:3.6.8-71.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-8194","fix":{"state":"fixed","versions":["0:3.6.8-71.el8_10"],"available":[{"date":"2025-08-27","kind":"first-observed","version":"0:3.6.8-71.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"risk":0.416875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14560","link":"https://access.redhat.com/errata/RHSA-2025:14560"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-8194","description":"A flaw was found in the Python tarfile module. Processing a specially crafted tar archive, specifically an archive with negative offsets, can cause an infinite loop and deadlock. This issue results in a denial of service in the Python application using the tarfile module."},"relatedVulnerabilities":[{"id":"CVE-2025-8194","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"urls":["https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38","https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227","https://github.com/python/cpython/issues/130577","https://github.com/python/cpython/pull/137027","https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/","http://www.openwall.com/lists/oss-security/2025/07/28/1","http://www.openwall.com/lists/oss-security/2025/07/28/2","https://github.com/python/cpython/pull/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/pull/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/pull/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/pull/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/pull/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/pull/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8194","description":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1"}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-71.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-8194","versionConstraint":"< 0:3.6.8-71.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-8194","fix":{"state":"fixed","versions":["0:3.6.8-71.el8_10"],"available":[{"date":"2025-08-27","kind":"first-observed","version":"0:3.6.8-71.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"risk":0.416875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14560","link":"https://access.redhat.com/errata/RHSA-2025:14560"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-8194","description":"A flaw was found in the Python tarfile module. Processing a specially crafted tar archive, specifically an archive with negative offsets, can cause an infinite loop and deadlock. This issue results in a denial of service in the Python application using the tarfile module."},"relatedVulnerabilities":[{"id":"CVE-2025-8194","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"urls":["https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38","https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227","https://github.com/python/cpython/issues/130577","https://github.com/python/cpython/pull/137027","https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/","http://www.openwall.com/lists/oss-security/2025/07/28/1","http://www.openwall.com/lists/oss-security/2025/07/28/2","https://github.com/python/cpython/pull/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/pull/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/pull/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/pull/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/pull/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/pull/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8194","description":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1"}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-8194","versionConstraint":"< 0:3.9.20-2.module+el8.10.0+23441+1124c1da (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-8194","fix":{"state":"fixed","versions":["0:3.9.20-2.module+el8.10.0+23441+1124c1da"],"available":[{"date":"2025-09-01","kind":"first-observed","version":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"risk":0.416875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14900","link":"https://access.redhat.com/errata/RHSA-2025:14900"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-8194","description":"A flaw was found in the Python tarfile module. Processing a specially crafted tar archive, specifically an archive with negative offsets, can cause an infinite loop and deadlock. This issue results in a denial of service in the Python application using the tarfile module."},"relatedVulnerabilities":[{"id":"CVE-2025-8194","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"urls":["https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38","https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227","https://github.com/python/cpython/issues/130577","https://github.com/python/cpython/pull/137027","https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/","http://www.openwall.com/lists/oss-security/2025/07/28/1","http://www.openwall.com/lists/oss-security/2025/07/28/2","https://github.com/python/cpython/pull/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/pull/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/pull/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/pull/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/pull/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/pull/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8194","description":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1"}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-8194","versionConstraint":"< 0:3.9.20-2.module+el8.10.0+23441+1124c1da (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-8194","fix":{"state":"fixed","versions":["0:3.9.20-2.module+el8.10.0+23441+1124c1da"],"available":[{"date":"2025-09-01","kind":"first-observed","version":"0:3.9.20-2.module+el8.10.0+23441+1124c1da"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"risk":0.416875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14900","link":"https://access.redhat.com/errata/RHSA-2025:14900"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-8194","description":"A flaw was found in the Python tarfile module. Processing a specially crafted tar archive, specifically an archive with negative offsets, can cause an infinite loop and deadlock. This issue results in a denial of service in the Python application using the tarfile module."},"relatedVulnerabilities":[{"id":"CVE-2025-8194","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8194","cwe":"CWE-835","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-8194","date":"2026-10-08","epss":0.00667,"percentile":0.50352}],"urls":["https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1","https://github.com/python/cpython/commit/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/commit/7040aa54f14676938970e10c5f74ea93cd56aa38","https://github.com/python/cpython/commit/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/commit/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/commit/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/commit/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/commit/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227","https://github.com/python/cpython/issues/130577","https://github.com/python/cpython/pull/137027","https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/","http://www.openwall.com/lists/oss-security/2025/07/28/1","http://www.openwall.com/lists/oss-security/2025/07/28/2","https://github.com/python/cpython/pull/57f5981d6260ed21266e0c26951b8564cc252bc2","https://github.com/python/cpython/pull/73f03e4808206f71eb6b92c579505a220942ef19","https://github.com/python/cpython/pull/b4ec17488eedec36d3c05fec127df71c0071f6cb","https://github.com/python/cpython/pull/c9d9f78feb1467e73fd29356c040bde1c104f29f","https://github.com/python/cpython/pull/cdae923ffe187d6ef916c0f665a31249619193fe","https://github.com/python/cpython/pull/fbc2a0ca9ac8aff6887f8ddf79b87b4510277227"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8194","description":"There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. \n\nThis vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1"}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-6395","versionConstraint":"< 0:3.6.16-8.el8_10.4 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6395","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.4"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.16-8.el8_10.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6395","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6395","date":"2026-10-08","epss":0.00717,"percentile":0.52395}],"risk":0.41227499999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:17415","link":"https://access.redhat.com/errata/RHSA-2025:17415"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6395","description":"A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()."},"relatedVulnerabilities":[{"id":"CVE-2025-6395","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6395","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6395","date":"2026-10-08","epss":0.00717,"percentile":0.52395}],"urls":["https://access.redhat.com/errata/RHSA-2025:16115","https://access.redhat.com/errata/RHSA-2025:16116","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:17348","https://access.redhat.com/errata/RHSA-2025:17361","https://access.redhat.com/errata/RHSA-2025:17415","https://access.redhat.com/errata/RHSA-2025:19088","https://access.redhat.com/errata/RHSA-2025:22529","https://access.redhat.com/security/cve/CVE-2025-6395","https://bugzilla.redhat.com/show_bug.cgi?id=2376755","https://gitlab.com/gnutls/gnutls/-/issues/1718","https://lists.gnupg.org/pipermail/gnutls-help/2025-July/004883.html","http://www.openwall.com/lists/oss-security/2025/07/11/3","https://lists.debian.org/debian-lts-announce/2025/08/msg00005.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6395","description":"A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite()."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.41112499999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11972","description":"A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in 'streaming mode' (mode='r|'), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.41112499999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11972","description":"A flaw was found in the Python `tarfile` module. When processing a specially crafted tar archive opened in 'streaming mode' (mode='r|'), the module does not properly handle the end-of-file (EOF) condition. This can cause the `tarfile` module to enter an infinite loop, leading to a Denial of Service (DoS) for applications processing such archives."},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"586e3395365fa6f0","cpes":["cpe:2.3:a:brotli:brotli:1.0.6-3.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:brotli:1.0.6-3.el8:*:*:*:*:*:*:*"],"name":"brotli","purl":"pkg:rpm/redhat/brotli@1.0.6-3.el8?arch=x86_64&distro=rhel-8.10&upstream=brotli-1.0.6-3.el8.src.rpm","type":"rpm","version":"1.0.6-3.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.0.6-4.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-6176","versionConstraint":"< 0:1.0.6-4.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"brotli","version":"0:1.0.6-3.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6176","fix":{"state":"fixed","versions":["0:1.0.6-4.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:1.0.6-4.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6176","cwe":"CWE-400","type":"Secondary","source":"security@huntr.dev"}],"epss":[{"cve":"CVE-2025-6176","date":"2026-10-08","epss":0.00545,"percentile":0.43947}],"risk":0.40875,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2389","link":"https://access.redhat.com/errata/RHSA-2026:2389"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6176","description":"Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression."},"relatedVulnerabilities":[{"id":"CVE-2025-6176","cvss":[{"type":"Secondary","source":"security@huntr.dev","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6176","cwe":"CWE-400","type":"Secondary","source":"security@huntr.dev"}],"epss":[{"cve":"CVE-2025-6176","date":"2026-10-08","epss":0.00545,"percentile":0.43947}],"urls":["https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6176","description":"Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69420","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-69420","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69420","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69420","date":"2026-10-08","epss":0.00899,"percentile":0.58405}],"risk":0.40005500000000005,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-69420","description":"A flaw was found in OpenSSL. A type confusion vulnerability exists in the TimeStamp Response verification code, where an ASN1_TYPE union member is accessed without proper type validation. A remote attacker can exploit this by providing a malformed TimeStamp Response to an application that verifies timestamp responses. This can lead to an invalid or NULL pointer dereference, resulting in a Denial of Service (DoS) due to an application crash."},"relatedVulnerabilities":[{"id":"CVE-2025-69420","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69420","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69420","date":"2026-10-08","epss":0.00899,"percentile":0.58405}],"urls":["https://github.com/openssl/openssl/commit/27c7012c91cc986a598d7540f3079dfde2416eb9","https://github.com/openssl/openssl/commit/4e254b48ad93cc092be3dd62d97015f33f73133a","https://github.com/openssl/openssl/commit/564fd9c73787f25693bf9e75faf7bf6bb1305d4e","https://github.com/openssl/openssl/commit/5eb0770ffcf11b785cf374ff3c19196245e54f1b","https://github.com/openssl/openssl/commit/a99349ebfc519999edc50620abe24d599b9eb085","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69420","description":"Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.39559999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11856","description":"A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.39559999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11856","description":"A flaw was found in curl. When `libcurl` performs a transfer to an HTTP origin using Digest authentication and then reuses the same connection handle for a subsequent transfer to a different origin, it may incorrectly send the authentication header intended for the first origin to the second. This could lead to unintended information disclosure, potentially allowing an attacker to gain unauthorized access to sensitive data."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.38625,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6253","description":"A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6253","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.38625,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6253","description":"A flaw was found in curl. When curl is configured to use distinct proxies for different URL schemes, a redirect from a URL using an authenticated proxy to one using an unauthenticated proxy can inadvertently expose the initial proxy's credentials. This improper credential management (CWE-522) may allow an attacker to gain unauthorized access or information by intercepting these disclosed credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6253","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"}]},{"artifact":{"id":"4afeeed91e127737","cpes":["cpe:2.3:a:libgcc:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.38505000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-27943","description":"A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"4fd2ded12bcd7931","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-27943","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2022-27943","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"risk":0.38505000000000006,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2022-27943","description":"A flaw was found in binutils, where GNU GCC is vulnerable to a denial of service caused by a stack consumption in the demangle_const() function in libiberty/rust-demangle.c. The vulnerability exists due to the application not properly controlling the consumption of internal resources. By persuading a victim to open a specially-crafted file, an attacker could cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2022-27943","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-27943","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-27943","date":"2026-10-08","epss":0.00906,"percentile":0.58638}],"urls":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=105039","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H424YXGW7OKXS2NCAP35OP6Y4P4AW6VG/","https://sourceware.org/bugzilla/show_bug.cgi?id=28995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-27943","description":"libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1:1.1.1k-15.el8_6"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69419","versionConstraint":"< 1:1.1.1k-15.el8_6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-69419","fix":{"state":"fixed","versions":["1:1.1.1k-15.el8_6"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"1:1.1.1k-15.el8_6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69419","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69419","date":"2026-10-08","epss":0.00616,"percentile":0.47921}],"risk":0.38192,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:3042","link":"https://access.redhat.com/errata/RHSA-2026:3042"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-69419","description":"A flaw was found in OpenSSL. When processing a specially crafted PKCS#12 (Personal Information Exchange Syntax Standard) file, a remote attacker can exploit an out-of-bounds write vulnerability. This issue, occurring within the OPENSSL_uni2utf8() function, leads to memory corruption by writing data beyond its allocated buffer. Successful exploitation could result in a denial of service or potentially allow for arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2025-69419","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69419","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-69419","date":"2026-10-08","epss":0.00616,"percentile":0.47921}],"urls":["https://github.com/openssl/openssl/commit/41be0f216404f14457bbf3b9cc488dba60b49296","https://github.com/openssl/openssl/commit/7e9cac9832e4705b91987c2474ed06a37a93cecb","https://github.com/openssl/openssl/commit/a26a90d38edec3748566129d824e664b54bee2e2","https://github.com/openssl/openssl/commit/cda12de3bc0e333ea8d2c6fd15001dbdaf280015","https://github.com/openssl/openssl/commit/ff628933755075446bca8307e8417c14d164b535","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69419","description":"Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously\ncrafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing\nnon-ASCII BMP code point can trigger a one byte write before the allocated\nbuffer.\n\nImpact summary: The out-of-bounds write can cause a memory corruption\nwhich can have various consequences including a Denial of Service.\n\nThe OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12\nBMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,\nthe helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16\nsource byte count as the destination buffer capacity to UTF8_putc(). For BMP\ncode points above U+07FF, UTF-8 requires three bytes, but the forwarded\ncapacity can be just two bytes. UTF8_putc() then returns -1, and this negative\nvalue is added to the output length without validation, causing the\nlength to become negative. The subsequent trailing NUL byte is then written\nat a negative offset, causing write outside of heap allocated buffer.\n\nThe vulnerability is reachable via the public PKCS12_get_friendlyname() API\nwhen parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a\ndifferent code path that avoids this issue, PKCS12_get_friendlyname() directly\ninvokes the vulnerable function. Exploitation requires an attacker to provide\na malicious PKCS#12 file to be parsed by the application and the attacker\ncan just trigger a one zero byte write before the allocated buffer.\nFor that reason the issue was assessed as Low severity according to our\nSecurity Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.380075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8924","description":"A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.380075,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8924","description":"A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.11.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.11.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5773","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5773","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.37777499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5773","description":"A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers."},"relatedVulnerabilities":[{"id":"CVE-2026-5773","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5773","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5773","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.37777499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5773","description":"A flaw was found in libcurl. Due to a logical error in the connection reuse mechanism for SMB (Server Message Block) transfers, libcurl might reuse an existing SMB connection with a different share than intended. This vulnerability, categorized as CWE-488 (Exposure of Data Element to Wrong Session), could lead to the download of an incorrect file or the upload of a file to an unintended location when an application uses libcurl for SMB transfers."},"relatedVulnerabilities":[{"id":"CVE-2026-5773","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4224","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4224","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"risk":0.37605000000000005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4224","description":"A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash."},"relatedVulnerabilities":[{"id":"CVE-2026-4224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"urls":["https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a","https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621","https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785","https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee","https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3","https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768","https://github.com/python/cpython/issues/145986","https://github.com/python/cpython/pull/145987","https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/","http://www.openwall.com/lists/oss-security/2026/03/16/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4224","description":"When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4224","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4224","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"risk":0.37605000000000005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4224","description":"A stack overflow flaw has been discovered in the python pyexpat module. When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. This will result in a program crash."},"relatedVulnerabilities":[{"id":"CVE-2026-4224","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4224","cwe":"CWE-674","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4224","date":"2026-10-08","epss":0.0069,"percentile":0.51296}],"urls":["https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a","https://github.com/python/cpython/commit/24ce88b285f56ee11626cf5e472af3cd8cc7c621","https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785","https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee","https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3","https://github.com/python/cpython/commit/eb0e8be3a7e11b87d198a2c3af1ed0eccf532768","https://github.com/python/cpython/issues/145986","https://github.com/python/cpython/pull/145987","https://mail.python.org/archives/list/security-announce@python.org/thread/5M7CGUW3XBRY7II4DK43KF7NQQ3TPZ6R/","http://www.openwall.com/lists/oss-security/2026/03/16/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4224","description":"When an Expat parser with a registered ElementDeclHandler parses an inline\ndocument type definition containing a deeply nested content model a C stack\noverflow occurs."}]},{"artifact":{"id":"c7d49258e4dd82db","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"899e5cf01be55fbf094ad72b2edb0c5df99111ee","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":"<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"e9a07c843cdc0167","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-core-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"b4f588bf070f77b604c645a7d60b71eae2e6ea09","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-core-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-core-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":"<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.375,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8927","description":"A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of `Proxy-Authorization` headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.375,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8927","description":"A flaw was found in libcurl. When reusing a libcurl handle for sequential transfers with environment-variable proxy configuration, the library does not properly clear the proxy authentication state. This oversight can lead to the unintended disclosure of `Proxy-Authorization` headers to an incorrect proxy, potentially exposing sensitive authentication information to an unauthorized entity. This is an information disclosure vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"eb28dc002400c573","cpes":["cpe:2.3:a:io.netty.codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-codec","purl":"pkg:maven/io.netty/netty-codec@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-codec","archiveDigests":[{"value":"307f665c08ce57333121de4f460479fc0c3c94d4","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.136.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-558v-64gr-wgg4","versionConstraint":"<4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-558v-64gr-wgg4","fix":{"state":"fixed","versions":["4.1.136.Final"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"4.1.136.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"risk":0.3726,"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4","https://github.com/netty/netty/releases/tag/netty-4.1.136.Final","https://github.com/netty/netty/releases/tag/netty-4.2.16.Final"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-558v-64gr-wgg4","description":"Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang"},"relatedVulnerabilities":[{"id":"CVE-2026-59901","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59901","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59901","date":"2026-10-08","epss":0.0046,"percentile":0.37877}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-558v-64gr-wgg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59901","description":"Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2BlockDecompressor.read()`]. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42013","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42013","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42013","date":"2026-10-08","epss":0.00564,"percentile":0.45129}],"risk":0.37223999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42013","description":"A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks."},"relatedVulnerabilities":[{"id":"CVE-2026-42013","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42013","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42013","date":"2026-10-08","epss":0.00564,"percentile":0.45129}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42013","https://bugzilla.redhat.com/show_bug.cgi?id=2467448","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42013","description":"A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks."}]},{"artifact":{"id":"2dd3466fcbd5ba1b","cpes":["cpe:2.3:a:jline-builtins:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline_builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline_builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_builtins:3.25.1:*:*:*:*:*:*:*"],"name":"jline-builtins","purl":"pkg:maven/org.jline/jline-builtins@3.25.1","type":"java-archive","version":"3.25.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.25.1.jar:org.jline:jline-builtins","manifestName":"","pomArtifactID":"jline-builtins","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.25.1.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jline-3.25.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r2xf-8xr9-62gw","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-builtins","version":"3.25.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r2xf-8xr9-62gw","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77422","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77422","date":"2026-10-08","epss":0.00496,"percentile":0.40617}],"risk":0.372,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r2xf-8xr9-62gw","description":"JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping"},"relatedVulnerabilities":[{"id":"CVE-2026-77422","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77422","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77422","date":"2026-10-08","epss":0.00496,"percentile":0.40617}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77422","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"f3dbf2601d631118","cpes":["cpe:2.3:a:python3-rpm:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-rpm:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_rpm:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_rpm:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"python3-rpm","purl":"pkg:rpm/redhat/python3-rpm@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.14.3-32.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95521","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-95521","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"risk":0.37184,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."},"relatedVulnerabilities":[{"id":"CVE-2026-95521","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95521","https://bugzilla.redhat.com/show_bug.cgi?id=2537812"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."}]},{"artifact":{"id":"6c723629f01508b1","cpes":["cpe:2.3:a:redhat:rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"rpm","purl":"pkg:rpm/redhat/rpm@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95521","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"0:4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-95521","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"risk":0.37184,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."},"relatedVulnerabilities":[{"id":"CVE-2026-95521","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95521","https://bugzilla.redhat.com/show_bug.cgi?id=2537812"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."}]},{"artifact":{"id":"e44a5dd2f875a462","cpes":["cpe:2.3:a:rpm-build-libs:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build-libs:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build_libs:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build_libs:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-build:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_build:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-build-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_build_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"rpm-build-libs","purl":"pkg:rpm/redhat/rpm-build-libs@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.14.3-32.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95521","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-95521","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"risk":0.37184,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."},"relatedVulnerabilities":[{"id":"CVE-2026-95521","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95521","https://bugzilla.redhat.com/show_bug.cgi?id=2537812"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."}]},{"artifact":{"id":"9c24e9e6f2be9987","cpes":["cpe:2.3:a:rpm-libs:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm-libs:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm_libs:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm-libs:4.14.3-32.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:rpm:rpm_libs:4.14.3-32.el8_10:*:*:*:*:*:*:*"],"name":"rpm-libs","purl":"pkg:rpm/redhat/rpm-libs@4.14.3-32.el8_10?arch=x86_64&distro=rhel-8.10&upstream=rpm-4.14.3-32.el8_10.src.rpm","type":"rpm","version":"4.14.3-32.el8_10","language":"","licenses":["GPLv2+ and LGPLv2+ with exceptions"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"rpm","version":"4.14.3-32.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95521","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"rpm","version":"4.14.3-32.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-95521","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"risk":0.37184,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."},"relatedVulnerabilities":[{"id":"CVE-2026-95521","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95521","cwe":"CWE-78","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95521","date":"2026-10-08","epss":0.00581,"percentile":0.46062}],"urls":["https://access.redhat.com/security/cve/CVE-2026-95521","https://bugzilla.redhat.com/show_bug.cgi?id=2537812"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95521","description":"A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15468","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15468","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15468","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-15468","date":"2026-10-08","epss":0.00831,"percentile":0.56284}],"risk":0.36979500000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15468","description":"A flaw was found in openssl. A remote attacker could trigger a NULL pointer dereference by sending an unknown or unsupported cipher ID during the client hello callback in applications using the QUIC (Quick UDP Internet Connections) protocol. This vulnerability, occurring when the SSL_CIPHER_find() function is called in this specific context, leads to an abnormal termination of the running process, causing a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2025-15468","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15468","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2025-15468","date":"2026-10-08","epss":0.00831,"percentile":0.56284}],"urls":["https://github.com/openssl/openssl/commit/1f08e54bad32843044fe8a675948d65e3b4ece65","https://github.com/openssl/openssl/commit/7c88376731c589ee5b36116c5a6e32d5ae5f7ae2","https://github.com/openssl/openssl/commit/b2539639400288a4580fe2d76247541b976bade4","https://github.com/openssl/openssl/commit/d75b309879631d45b972396ce4e5102559c64ac7","https://openssl-library.org/news/secadv/20260127.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15468","description":"Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\n\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\n\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\n\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\n\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue."}]},{"artifact":{"id":"c7d49258e4dd82db","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"899e5cf01be55fbf094ad72b2edb0c5df99111ee","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"e9a07c843cdc0167","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-core-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"b4f588bf070f77b604c645a7d60b71eae2e6ea09","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-core-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-core-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4435","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4435","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.36874999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4435","description":"A flaw was found in CPython's tarfile module. This vulnerability allows unauthorized file extraction via crafted tar archives when TarFile.errorlevel=0, bypassing expected filtering mechanisms."},"relatedVulnerabilities":[{"id":"CVE-2025-4435","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4435","description":"When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-70.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4435","versionConstraint":"< 0:3.6.8-70.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4435","fix":{"state":"fixed","versions":["0:3.6.8-70.el8_10"],"available":[{"date":"2025-07-03","kind":"first-observed","version":"0:3.6.8-70.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.36874999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10128","link":"https://access.redhat.com/errata/RHSA-2025:10128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4435","description":"A flaw was found in CPython's tarfile module. This vulnerability allows unauthorized file extraction via crafted tar archives when TarFile.errorlevel=0, bypassing expected filtering mechanisms."},"relatedVulnerabilities":[{"id":"CVE-2025-4435","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4435","description":"When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-4435","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4435","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.36874999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4435","description":"A flaw was found in CPython's tarfile module. This vulnerability allows unauthorized file extraction via crafted tar archives when TarFile.errorlevel=0, bypassing expected filtering mechanisms."},"relatedVulnerabilities":[{"id":"CVE-2025-4435","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4435","description":"When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4435","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4435","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.36874999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4435","description":"A flaw was found in CPython's tarfile module. This vulnerability allows unauthorized file extraction via crafted tar archives when TarFile.errorlevel=0, bypassing expected filtering mechanisms."},"relatedVulnerabilities":[{"id":"CVE-2025-4435","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4435","cwe":"CWE-682","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-4435","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da","https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9","https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a","https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e","https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a","https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a","https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01","https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1","https://github.com/python/cpython/issues/135034","https://github.com/python/cpython/pull/135037","https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4435","description":"When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.368225,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3276","description":"A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3276","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.368225,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3276","description":"A flaw was found in the `unicodedata.normalize()` function in Python. This vulnerability allows a remote attacker to cause excessive CPU consumption by providing specially crafted Unicode input. Successful exploitation can lead to a Denial of Service (DoS) on the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-3276","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3276","cwe":"CWE-407","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-3276","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/6b505d1f41f8f3ea0fe5a4786d3a8fff1875cfc0","https://github.com/python/cpython/commit/90748760d38ca3ac5fc6788a69becab905c95598","https://github.com/python/cpython/commit/991224b1e8311c85f198f6dd8208bf8cff7fc26f","https://github.com/python/cpython/commit/ba785b88add96acbf403d65cb157fb2743a33a32","https://github.com/python/cpython/commit/c5512bd7c1dc28055660565275012766941d3066","https://github.com/python/cpython/commit/d3ab945af25b28dfe13ac6cb40c124a01b33ce1f","https://github.com/python/cpython/commit/db744c0776c1d5dd11aaa70eff2a6993c408bacc","https://github.com/python/cpython/commit/e322a1857084d521f79f45181b776f62e6acfc2c","https://github.com/python/cpython/issues/149079","https://github.com/python/cpython/pull/149080","https://mail.python.org/archives/list/security-announce@python.org/thread/PP5HB4K7727OBBM76KA2ILID76K3OZGZ/","http://www.openwall.com/lists/oss-security/2026/06/03/15"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3276","description":"unicodedata.normalize() can take excessive CPU time when processing\nspecially crafted Unicode input containing long runs of combining characters\nwith alternating Canonical Combining Class values.\nThis affects all normalization forms."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-9287","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-9287","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9287","cwe":"CWE-428","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-9287","cwe":"CWE-77","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9287","date":"2026-10-08","epss":0.00648,"percentile":0.4946}],"risk":0.36611999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-9287","description":"A vulnerability has been found in the Python `venv` module and CLI. Path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment \"activation\" scripts, for example, \"source venv/bin/activate\". This flaw allows attacker-controlled virtual environments to run commands when the virtual environment is activated."},"relatedVulnerabilities":[{"id":"CVE-2024-9287","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9287","cwe":"CWE-428","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-9287","cwe":"CWE-77","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9287","date":"2026-10-08","epss":0.00648,"percentile":0.4946}],"urls":["https://github.com/python/cpython/commit/633555735a023d3e4d92ba31da35b1205f9ecbd7","https://github.com/python/cpython/commit/8450b2482586857d689b6658f08de9c8179af7db","https://github.com/python/cpython/commit/9286ab3a107ea41bd3f3c3682ce2512692bdded8","https://github.com/python/cpython/commit/ae961ae94bf19c8f8c7fbea3d1c25cc55ce8ae97","https://github.com/python/cpython/commit/d48cc82ed25e26b02eb97c6263d95dcaa1e9111b","https://github.com/python/cpython/commit/e52095a0c1005a87eed2276af7a1f2f66e2b6483","https://github.com/python/cpython/issues/124651","https://github.com/python/cpython/pull/124712","https://mail.python.org/archives/list/security-announce@python.org/thread/RSPJ2B5JL22FG3TKUJ7D7DQ4N5JRRBZL/","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250425-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9287","description":"A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment \"activation\" scripts (ie \"source venv/bin/activate\"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie \"./venv/bin/python\") are not affected."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-9287","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-9287","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9287","cwe":"CWE-428","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-9287","cwe":"CWE-77","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9287","date":"2026-10-08","epss":0.00648,"percentile":0.4946}],"risk":0.36611999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-9287","description":"A vulnerability has been found in the Python `venv` module and CLI. Path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment \"activation\" scripts, for example, \"source venv/bin/activate\". This flaw allows attacker-controlled virtual environments to run commands when the virtual environment is activated."},"relatedVulnerabilities":[{"id":"CVE-2024-9287","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-9287","cwe":"CWE-428","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2024-9287","cwe":"CWE-77","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-9287","date":"2026-10-08","epss":0.00648,"percentile":0.4946}],"urls":["https://github.com/python/cpython/commit/633555735a023d3e4d92ba31da35b1205f9ecbd7","https://github.com/python/cpython/commit/8450b2482586857d689b6658f08de9c8179af7db","https://github.com/python/cpython/commit/9286ab3a107ea41bd3f3c3682ce2512692bdded8","https://github.com/python/cpython/commit/ae961ae94bf19c8f8c7fbea3d1c25cc55ce8ae97","https://github.com/python/cpython/commit/d48cc82ed25e26b02eb97c6263d95dcaa1e9111b","https://github.com/python/cpython/commit/e52095a0c1005a87eed2276af7a1f2f66e2b6483","https://github.com/python/cpython/issues/124651","https://github.com/python/cpython/pull/124712","https://mail.python.org/archives/list/security-announce@python.org/thread/RSPJ2B5JL22FG3TKUJ7D7DQ4N5JRRBZL/","https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250425-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-9287","description":"A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment \"activation\" scripts (ie \"source venv/bin/activate\"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie \"./venv/bin/python\") are not affected."}]},{"artifact":{"id":"eb28dc002400c573","cpes":["cpe:2.3:a:io.netty.codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-codec","purl":"pkg:maven/io.netty/netty-codec@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-codec","archiveDigests":[{"value":"307f665c08ce57333121de4f460479fc0c3c94d4","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.133.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mj4r-2hfc-f8p6","versionConstraint":"<=4.1.132.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-mj4r-2hfc-f8p6","fix":{"state":"fixed","versions":["4.1.133.Final"],"available":[{"date":"2026-05-07","kind":"first-observed","version":"4.1.133.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42583","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42583","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42583","date":"2026-10-08","epss":0.00486,"percentile":0.39915}],"risk":0.3645,"urls":["https://github.com/netty/netty/security/advisories/GHSA-mj4r-2hfc-f8p6","https://nvd.nist.gov/vuln/detail/CVE-2026-42583"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mj4r-2hfc-f8p6","description":"Netty Lz4FrameDecoder is vulnerable to resource exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-42583","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42583","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42583","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-42583","date":"2026-10-08","epss":0.00486,"percentile":0.39915}],"urls":["https://github.com/netty/netty/security/advisories/GHSA-mj4r-2hfc-f8p6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42583","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus compressedLength payload bytes - 22 bytes if compressedLength == 1 - to force that allocation. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-21.el8_10.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-32415","versionConstraint":"< 0:2.9.7-21.el8_10.3 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-32415","fix":{"state":"fixed","versions":["0:2.9.7-21.el8_10.3"],"available":[{"date":"2025-08-08","kind":"first-observed","version":"0:2.9.7-21.el8_10.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32415","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-32415","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-32415","date":"2026-10-08","epss":0.0058,"percentile":0.45988}],"risk":0.3625,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:13203","link":"https://access.redhat.com/errata/RHSA-2025:13203"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-32415","description":"A flaw was found in the libxml2 library. A heap-based underflow can be triggered when a crafted XML document is validated against an XML schema with certain identity constraints or when a crafted XML schema is used, causing a crash to the application linked to the library and resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2025-32415","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32415","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-32415","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-32415","date":"2026-10-08","epss":0.0058,"percentile":0.45988}],"urls":["https://gitlab.gnome.org/GNOME/libxml2/-/issues/890","https://lists.debian.org/debian-lts-announce/2025/04/msg00041.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32415","description":"In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used."}]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-2.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-45186","versionConstraint":"< 0:2.5.0-2.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-45186","fix":{"state":"fixed","versions":["0:2.5.0-2.el8_10"],"available":[{"date":"2026-06-04","kind":"first-observed","version":"0:2.5.0-2.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45186","date":"2026-10-08","epss":0.00479,"percentile":0.39397}],"risk":0.35925,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:22721","link":"https://access.redhat.com/errata/RHSA-2026:22721"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-45186","description":"A flaw was found in libexpat. When processing a specially crafted XML input containing a specific pattern of attributes, the parsing time increases quadratically due to checks for attribute name collisions. This consumes excessive CPU resources and eventually results in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-45186","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-45186","cwe":"CWE-407","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-45186","date":"2026-10-08","epss":0.00479,"percentile":0.39397}],"urls":["https://github.com/libexpat/libexpat/pull/1216","http://www.openwall.com/lists/oss-security/2026/05/11/16","https://access.redhat.com/errata/RHSA-2026:22715","https://access.redhat.com/errata/RHSA-2026:22721","https://access.redhat.com/errata/RHSA-2026:23230","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:27201","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-45186","https://bugzilla.redhat.com/show_bug.cgi?id=2468575","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45186","description":"In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.38"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 0:2.28-251.el8_10.38 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.38"],"available":[{"date":"2026-06-30","kind":"first-observed","version":"0:2.28-251.el8_10.38"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:33126","link":"https://access.redhat.com/errata/RHSA-2026:33126"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5450","description":"A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.38"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 0:2.28-251.el8_10.38 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.38"],"available":[{"date":"2026-06-30","kind":"first-observed","version":"0:2.28-251.el8_10.38"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:33126","link":"https://access.redhat.com/errata/RHSA-2026:33126"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5450","description":"A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.38"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 0:2.28-251.el8_10.38 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.38"],"available":[{"date":"2026-06-30","kind":"first-observed","version":"0:2.28-251.el8_10.38"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:33126","link":"https://access.redhat.com/errata/RHSA-2026:33126"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5450","description":"A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.38"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5450","versionConstraint":"< 0:2.28-251.el8_10.38 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5450","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.38"],"available":[{"date":"2026-06-30","kind":"first-observed","version":"0:2.28-251.el8_10.38"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"risk":0.359,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:33126","link":"https://access.redhat.com/errata/RHSA-2026:33126"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5450","description":"A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the `scanf` family of functions with a `%mc` format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory."},"relatedVulnerabilities":[{"id":"CVE-2026-5450","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5450","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-5450","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5450","date":"2026-10-08","epss":0.00718,"percentile":0.52433}],"urls":["https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5450","description":"Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow."}]},{"artifact":{"id":"eb28dc002400c573","cpes":["cpe:2.3:a:io.netty.codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:codec:codec:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:codec:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-codec","purl":"pkg:maven/io.netty/netty-codec@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-codec","archiveDigests":[{"value":"307f665c08ce57333121de4f460479fc0c3c94d4","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-codec-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.125.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3p8m-j85q-pgmj","versionConstraint":"<4.1.125.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-codec","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3p8m-j85q-pgmj","fix":{"state":"fixed","versions":["4.1.125.Final"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"4.1.125.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58057","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-58057","date":"2026-10-08","epss":0.00601,"percentile":0.47124}],"risk":0.35759499999999994,"urls":["https://github.com/netty/netty/security/advisories/GHSA-3p8m-j85q-pgmj","https://github.com/netty/netty/commit/9d804c54ce962408ae6418255a83a13924f7145d","https://nvd.nist.gov/vuln/detail/CVE-2025-58057"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3p8m-j85q-pgmj","description":"Netty's decoders vulnerable to DoS via zip bomb style attack"},"relatedVulnerabilities":[{"id":"CVE-2025-58057","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58057","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-58057","date":"2026-10-08","epss":0.00601,"percentile":0.47124}],"urls":["https://github.com/netty/netty/commit/9d804c54ce962408ae6418255a83a13924f7145d","https://github.com/netty/netty/security/advisories/GHSA-3p8m-j85q-pgmj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58057","description":"Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-32636","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-32636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32636","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-32636","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-32636","date":"2026-10-08","epss":0.00774,"percentile":0.54361}],"risk":0.35604,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-32636","description":"A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499."},"relatedVulnerabilities":[{"id":"CVE-2023-32636","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-32636","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-32636","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-32636","date":"2026-10-08","epss":0.00774,"percentile":0.54361}],"urls":["https://gitlab.gnome.org/GNOME/glib/-/issues/2841","https://https://discourse.gnome.org/t/multiple-fixes-for-gvariant-normalisation-issues-in-glib/12835","https://security.netapp.com/advisory/ntap-20231110-0002/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-32636","description":"A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-76.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4786","versionConstraint":"< 0:3.6.8-76.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4786","fix":{"state":"fixed","versions":["0:3.6.8-76.el8_10"],"available":[{"date":"2026-04-28","kind":"first-observed","version":"0:3.6.8-76.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4786","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-4786","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4786","date":"2026-10-08","epss":0.00485,"percentile":0.39795}],"risk":0.35405,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:11077","link":"https://access.redhat.com/errata/RHSA-2026:11077"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4786","description":"A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing \"%action\" is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-4786","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4786","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-4786","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4786","date":"2026-10-08","epss":0.00485,"percentile":0.39795}],"urls":["https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53","https://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744","https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca","https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff","https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4","https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769","https://github.com/python/cpython/issues/148169","https://github.com/python/cpython/pull/148170","https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/","https://access.redhat.com/errata/RHSA-2026:10117","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10711","https://access.redhat.com/errata/RHSA-2026:10745","https://access.redhat.com/errata/RHSA-2026:10774","https://access.redhat.com/errata/RHSA-2026:10949","https://access.redhat.com/errata/RHSA-2026:10950","https://access.redhat.com/errata/RHSA-2026:11062","https://access.redhat.com/errata/RHSA-2026:11077","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:13692","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14652","https://access.redhat.com/errata/RHSA-2026:14653","https://access.redhat.com/errata/RHSA-2026:14656","https://access.redhat.com/errata/RHSA-2026:16699","https://access.redhat.com/errata/RHSA-2026:17525","https://access.redhat.com/errata/RHSA-2026:17619","https://access.redhat.com/errata/RHSA-2026:19019","https://access.redhat.com/errata/RHSA-2026:19064","https://access.redhat.com/errata/RHSA-2026:19175","https://access.redhat.com/errata/RHSA-2026:19176","https://access.redhat.com/errata/RHSA-2026:19177","https://access.redhat.com/errata/RHSA-2026:19216","https://access.redhat.com/errata/RHSA-2026:19549","https://access.redhat.com/errata/RHSA-2026:19570","https://access.redhat.com/errata/RHSA-2026:19571","https://access.redhat.com/errata/RHSA-2026:19576","https://access.redhat.com/errata/RHSA-2026:19589","https://access.redhat.com/errata/RHSA-2026:19590","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:21682","https://access.redhat.com/errata/RHSA-2026:22144","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:26187","https://access.redhat.com/errata/RHSA-2026:28247","https://access.redhat.com/errata/RHSA-2026:28581","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:35838","https://access.redhat.com/errata/RHSA-2026:8822","https://access.redhat.com/errata/RHSA-2026:8824","https://access.redhat.com/errata/RHSA-2026:9228","https://access.redhat.com/security/cve/CVE-2026-4786","https://bugzilla.redhat.com/show_bug.cgi?id=2458049","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4786","description":"Mitgation of CVE-2026-4519 was incomplete. If the URL contained \"%action\" the mitigation could be bypassed for certain browser types the \"webbrowser.open()\" API could have commands injected into the underlying shell. See CVE-2026-4519 for details."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-76.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4786","versionConstraint":"< 0:3.6.8-76.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4786","fix":{"state":"fixed","versions":["0:3.6.8-76.el8_10"],"available":[{"date":"2026-04-28","kind":"first-observed","version":"0:3.6.8-76.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4786","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-4786","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4786","date":"2026-10-08","epss":0.00485,"percentile":0.39795}],"risk":0.35405,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:11077","link":"https://access.redhat.com/errata/RHSA-2026:11077"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4786","description":"A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing \"%action\" is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution."},"relatedVulnerabilities":[{"id":"CVE-2026-4786","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4786","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-4786","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4786","date":"2026-10-08","epss":0.00485,"percentile":0.39795}],"urls":["https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53","https://github.com/python/cpython/commit/a4d3edf3a6ecfde504d02126410d2a65a859b744","https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca","https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff","https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4","https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769","https://github.com/python/cpython/issues/148169","https://github.com/python/cpython/pull/148170","https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/","https://access.redhat.com/errata/RHSA-2026:10117","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10711","https://access.redhat.com/errata/RHSA-2026:10745","https://access.redhat.com/errata/RHSA-2026:10774","https://access.redhat.com/errata/RHSA-2026:10949","https://access.redhat.com/errata/RHSA-2026:10950","https://access.redhat.com/errata/RHSA-2026:11062","https://access.redhat.com/errata/RHSA-2026:11077","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:13692","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:14652","https://access.redhat.com/errata/RHSA-2026:14653","https://access.redhat.com/errata/RHSA-2026:14656","https://access.redhat.com/errata/RHSA-2026:16699","https://access.redhat.com/errata/RHSA-2026:17525","https://access.redhat.com/errata/RHSA-2026:17619","https://access.redhat.com/errata/RHSA-2026:19019","https://access.redhat.com/errata/RHSA-2026:19064","https://access.redhat.com/errata/RHSA-2026:19175","https://access.redhat.com/errata/RHSA-2026:19176","https://access.redhat.com/errata/RHSA-2026:19177","https://access.redhat.com/errata/RHSA-2026:19216","https://access.redhat.com/errata/RHSA-2026:19549","https://access.redhat.com/errata/RHSA-2026:19570","https://access.redhat.com/errata/RHSA-2026:19571","https://access.redhat.com/errata/RHSA-2026:19576","https://access.redhat.com/errata/RHSA-2026:19589","https://access.redhat.com/errata/RHSA-2026:19590","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:21682","https://access.redhat.com/errata/RHSA-2026:22144","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:26187","https://access.redhat.com/errata/RHSA-2026:28247","https://access.redhat.com/errata/RHSA-2026:28581","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:35838","https://access.redhat.com/errata/RHSA-2026:8822","https://access.redhat.com/errata/RHSA-2026:8824","https://access.redhat.com/errata/RHSA-2026:9228","https://access.redhat.com/security/cve/CVE-2026-4786","https://bugzilla.redhat.com/show_bug.cgi?id=2458049","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4786.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4786","description":"Mitgation of CVE-2026-4519 was incomplete. If the URL contained \"%action\" the mitigation could be bypassed for certain browser types the \"webbrowser.open()\" API could have commands injected into the underlying shell. See CVE-2026-4519 for details."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.22"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-4802","versionConstraint":"< 0:2.28-251.el8_10.22 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4802","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.22"],"available":[{"date":"2025-06-11","kind":"first-observed","version":"0:2.28-251.el8_10.22"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.354,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:8686","link":"https://access.redhat.com/errata/RHSA-2025:8686"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4802","description":"A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2025-4802","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32976","https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e","http://www.openwall.com/lists/oss-security/2025/05/16/7","http://www.openwall.com/lists/oss-security/2025/05/17/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00033.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4802","description":"Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo)."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.22"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4802","versionConstraint":"< 0:2.28-251.el8_10.22 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4802","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.22"],"available":[{"date":"2025-06-11","kind":"first-observed","version":"0:2.28-251.el8_10.22"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.354,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:8686","link":"https://access.redhat.com/errata/RHSA-2025:8686"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4802","description":"A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2025-4802","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32976","https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e","http://www.openwall.com/lists/oss-security/2025/05/16/7","http://www.openwall.com/lists/oss-security/2025/05/17/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00033.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4802","description":"Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo)."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.22"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4802","versionConstraint":"< 0:2.28-251.el8_10.22 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4802","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.22"],"available":[{"date":"2025-06-11","kind":"first-observed","version":"0:2.28-251.el8_10.22"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.354,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:8686","link":"https://access.redhat.com/errata/RHSA-2025:8686"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4802","description":"A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2025-4802","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32976","https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e","http://www.openwall.com/lists/oss-security/2025/05/16/7","http://www.openwall.com/lists/oss-security/2025/05/17/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00033.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4802","description":"Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo)."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.22"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-4802","versionConstraint":"< 0:2.28-251.el8_10.22 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4802","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.22"],"available":[{"date":"2025-06-11","kind":"first-observed","version":"0:2.28-251.el8_10.22"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"risk":0.354,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:8686","link":"https://access.redhat.com/errata/RHSA-2025:8686"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4802","description":"A flaw was found in the glibc library. A statically linked setuid binary that calls dlopen(), including internal dlopen() calls after setlocale() or calls to NSS functions such as getaddrinfo(), may incorrectly search LD_LIBRARY_PATH to determine which library to load, allowing a local attacker to load malicious shared libraries, escalate privileges and execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2025-4802","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4802","cwe":"CWE-426","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-4802","date":"2026-10-08","epss":0.0059,"percentile":0.46556}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=32976","https://sourceware.org/cgit/glibc/commit/?id=1e18586c5820e329f741d5c710275e165581380e","http://www.openwall.com/lists/oss-security/2025/05/16/7","http://www.openwall.com/lists/oss-security/2025/05/17/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00033.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4802","description":"Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo)."}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5351","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-5351","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5351","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5351","date":"2026-10-08","epss":0.00615,"percentile":0.47851}],"risk":0.35362499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5351","description":"A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed."},"relatedVulnerabilities":[{"id":"CVE-2025-5351","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5351","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5351","date":"2026-10-08","epss":0.00615,"percentile":0.47851}],"urls":["https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/security/cve/CVE-2025-5351","https://bugzilla.redhat.com/show_bug.cgi?id=2369367"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5351","description":"A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-5351","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-5351","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5351","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5351","date":"2026-10-08","epss":0.00615,"percentile":0.47851}],"risk":0.35362499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5351","description":"A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed."},"relatedVulnerabilities":[{"id":"CVE-2025-5351","cvss":[{"type":"Secondary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5351","cwe":"CWE-415","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5351","date":"2026-10-08","epss":0.00615,"percentile":0.47851}],"urls":["https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/security/cve/CVE-2025-5351","https://bugzilla.redhat.com/show_bug.cgi?id=2369367"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5351","description":"A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition may result in heap corruption or application instability in low-memory scenarios, posing a risk to system reliability where key export operations are performed."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42011","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42011","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42011","date":"2026-10-08","epss":0.0057,"percentile":0.45419}],"risk":0.35340000000000005,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42011","description":"A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems."},"relatedVulnerabilities":[{"id":"CVE-2026-42011","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42011","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42011","date":"2026-10-08","epss":0.0057,"percentile":0.45419}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:40762","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:57483","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59831","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42011","https://bugzilla.redhat.com/show_bug.cgi?id=2467437","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42011","description":"A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when previous Certificate Authorities (CAs) only had excluded name constraints. A remote attacker could exploit this to bypass critical name constraint checks during certificate validation. This bypass could lead to the acceptance of invalid certificates, potentially enabling spoofing or man-in-the-middle attacks against affected systems."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1299","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-1299","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1299","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1299","date":"2026-10-08","epss":0.00582,"percentile":0.46105}],"risk":0.35211,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1299","description":"A flaw was found in the email module in the Python standard library. When serializing an email message, the BytesGenerator class fails to properly quote newline characters for email headers. This issue is exploitable when the LiteralHeader class is used as it does not respect email folding rules, allowing an attacker to inject email headers and potentially modify message recipients or the email body, and spoof sender information."},"relatedVulnerabilities":[{"id":"CVE-2026-1299","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1299","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1299","date":"2026-10-08","epss":0.00582,"percentile":0.46105}],"urls":["https://cve.org/CVERecord?id=CVE-2024-6923","https://github.com/python/cpython/commit/052e55e7d44718fe46cbba0ca995cb8fcc359413","https://github.com/python/cpython/commit/0a925ab591c45d6638f37b5e57796f36fa0e56d8","https://github.com/python/cpython/commit/7877fe424415bc4a13045e62a90a7277413d8cb9","https://github.com/python/cpython/commit/842ce19a0c0b58d61591e8f6a708c38db1fb94e4","https://github.com/python/cpython/commit/8cdf6204f4ae821f32993f8fc6bad0d318f95f36","https://github.com/python/cpython/commit/e417f05ad77a4c30ddc07f99e90fc0cef43e831a","https://github.com/python/cpython/issues/144125","https://github.com/python/cpython/pull/144126","https://mail.python.org/archives/list/security-announce@python.org/thread/6ZZULGALJTITEAGEXLDJE2C6FORDXPBT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1299","description":"The \nemail module, specifically the \"BytesGenerator\" class, didn’t properly quote newlines for email headers when \nserializing an email message allowing for header injection when an email\n is serialized. This is only applicable if using \"LiteralHeader\" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in \"BytesGenerator\"."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1299","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-1299","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1299","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1299","date":"2026-10-08","epss":0.00582,"percentile":0.46105}],"risk":0.35211,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1299","description":"A flaw was found in the email module in the Python standard library. When serializing an email message, the BytesGenerator class fails to properly quote newline characters for email headers. This issue is exploitable when the LiteralHeader class is used as it does not respect email folding rules, allowing an attacker to inject email headers and potentially modify message recipients or the email body, and spoof sender information."},"relatedVulnerabilities":[{"id":"CVE-2026-1299","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1299","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1299","date":"2026-10-08","epss":0.00582,"percentile":0.46105}],"urls":["https://cve.org/CVERecord?id=CVE-2024-6923","https://github.com/python/cpython/commit/052e55e7d44718fe46cbba0ca995cb8fcc359413","https://github.com/python/cpython/commit/0a925ab591c45d6638f37b5e57796f36fa0e56d8","https://github.com/python/cpython/commit/7877fe424415bc4a13045e62a90a7277413d8cb9","https://github.com/python/cpython/commit/842ce19a0c0b58d61591e8f6a708c38db1fb94e4","https://github.com/python/cpython/commit/8cdf6204f4ae821f32993f8fc6bad0d318f95f36","https://github.com/python/cpython/commit/e417f05ad77a4c30ddc07f99e90fc0cef43e831a","https://github.com/python/cpython/issues/144125","https://github.com/python/cpython/pull/144126","https://mail.python.org/archives/list/security-announce@python.org/thread/6ZZULGALJTITEAGEXLDJE2C6FORDXPBT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1299","description":"The \nemail module, specifically the \"BytesGenerator\" class, didn’t properly quote newlines for email headers when \nserializing an email message allowing for header injection when an email\n is serialized. This is only applicable if using \"LiteralHeader\" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in \"BytesGenerator\"."}]},{"artifact":{"id":"5aa1877466828f16","cpes":["cpe:2.3:a:redhat:pam:1.3.1-36.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:pam:pam:1.3.1-36.el8_10:*:*:*:*:*:*:*"],"name":"pam","purl":"pkg:rpm/redhat/pam@1.3.1-36.el8_10?arch=x86_64&distro=rhel-8.10&upstream=pam-1.3.1-36.el8_10.src.rpm","type":"rpm","version":"1.3.1-36.el8_10","language":"","licenses":["BSD and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.3.1-37.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-6020","versionConstraint":"< 0:1.3.1-37.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"pam","version":"0:1.3.1-36.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6020","fix":{"state":"fixed","versions":["0:1.3.1-37.el8_10"],"available":[{"date":"2025-08-27","kind":"first-observed","version":"0:1.3.1-37.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-08","epss":0.0046,"percentile":0.37929}],"risk":0.3519,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:10027","link":"https://access.redhat.com/errata/RHSA-2025:10027"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6020","description":"A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions."},"relatedVulnerabilities":[{"id":"CVE-2025-6020","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6020","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-6020","date":"2026-10-08","epss":0.0046,"percentile":0.37929}],"urls":["https://access.redhat.com/errata/RHSA-2025:10024","https://access.redhat.com/errata/RHSA-2025:10027","https://access.redhat.com/errata/RHSA-2025:10180","https://access.redhat.com/errata/RHSA-2025:10354","https://access.redhat.com/errata/RHSA-2025:10357","https://access.redhat.com/errata/RHSA-2025:10358","https://access.redhat.com/errata/RHSA-2025:10359","https://access.redhat.com/errata/RHSA-2025:10361","https://access.redhat.com/errata/RHSA-2025:10362","https://access.redhat.com/errata/RHSA-2025:10735","https://access.redhat.com/errata/RHSA-2025:10823","https://access.redhat.com/errata/RHSA-2025:11386","https://access.redhat.com/errata/RHSA-2025:11487","https://access.redhat.com/errata/RHSA-2025:14557","https://access.redhat.com/errata/RHSA-2025:15099","https://access.redhat.com/errata/RHSA-2025:15709","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:16524","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:20181","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:22019","https://access.redhat.com/errata/RHSA-2025:9526","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/security/cve/CVE-2025-6020","https://bugzilla.redhat.com/show_bug.cgi?id=2372512","https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx","http://www.openwall.com/lists/oss-security/2025/06/17/1","https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6020","description":"A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2023-29499","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-29499","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29499","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-29499","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29499","date":"2026-10-08","epss":0.00761,"percentile":0.53936}],"risk":0.3500599999999999,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-29499","description":"A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service."},"relatedVulnerabilities":[{"id":"CVE-2023-29499","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-29499","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2023-29499","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-29499","date":"2026-10-08","epss":0.00761,"percentile":0.53936}],"urls":["https://access.redhat.com/security/cve/CVE-2023-29499","https://bugzilla.redhat.com/show_bug.cgi?id=2211828","https://gitlab.gnome.org/GNOME/glib/-/issues/2794","https://lists.debian.org/debian-lts-announce/2023/09/msg00030.html","https://security.gentoo.org/glsa/202311-18","https://security.netapp.com/advisory/ntap-20231103-0001/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-29499","description":"A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-21.el8_10.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-74860","versionConstraint":"< 0:2.9.7-21.el8_10.9 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-74860","fix":{"state":"fixed","versions":["0:2.9.7-21.el8_10.9"],"available":[{"date":"2026-09-25","kind":"first-observed","version":"0:2.9.7-21.el8_10.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"risk":0.3488,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:71641","link":"https://access.redhat.com/errata/RHSA-2026:71641"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."},"relatedVulnerabilities":[{"id":"CVE-2026-74860","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.5,"impactScore":6.1,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-74860","cwe":"CWE-763","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-74860","date":"2026-10-08","epss":0.00436,"percentile":0.35841}],"urls":["https://access.redhat.com/errata/RHSA-2026:64463","https://access.redhat.com/errata/RHSA-2026:71585","https://access.redhat.com/errata/RHSA-2026:71586","https://access.redhat.com/errata/RHSA-2026:71641","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/security/cve/CVE-2026-74860","https://bugzilla.redhat.com/show_bug.cgi?id=2529697"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-74860","description":"A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.34456,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6019","description":"A flaw was found in Python's `http.cookies` module. The `Morsel.js_output()` function, responsible for generating JavaScript output for cookies, does not properly neutralize the `</script>` HTML sequence. This oversight could allow a remote attacker to inject malicious script into a web page, potentially leading to Cross-Site Scripting (XSS) attacks. Such an attack could result in information disclosure or arbitrary code execution within the user's browser."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6019","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6019","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"risk":0.34456,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6019","description":"A flaw was found in Python's `http.cookies` module. The `Morsel.js_output()` function, responsible for generating JavaScript output for cookies, does not properly neutralize the `</script>` HTML sequence. This oversight could allow a remote attacker to inject malicious script into a web page, potentially leading to Cross-Site Scripting (XSS) attacks. Such an attack could result in information disclosure or arbitrary code execution within the user's browser."},"relatedVulnerabilities":[{"id":"CVE-2026-6019","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6019","cwe":"CWE-150","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-6019","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6019","date":"2026-10-08","epss":0.00584,"percentile":0.46224}],"urls":["https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c","https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104","https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8","https://github.com/python/cpython/issues/90309","https://github.com/python/cpython/pull/148848","https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6019","description":"http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes \" for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-14831","versionConstraint":"< 0:3.6.16-8.el8_10.5 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-14831","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.5"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.16-8.el8_10.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14831","cwe":"CWE-407","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14831","date":"2026-10-08","epss":0.00666,"percentile":0.50289}],"risk":0.34299,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:5585","link":"https://access.redhat.com/errata/RHSA-2026:5585"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14831","description":"A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs)."},"relatedVulnerabilities":[{"id":"CVE-2025-14831","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14831","cwe":"CWE-407","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14831","date":"2026-10-08","epss":0.00666,"percentile":0.50289}],"urls":["https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:3477","https://access.redhat.com/errata/RHSA-2026:4188","https://access.redhat.com/errata/RHSA-2026:4655","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:5585","https://access.redhat.com/errata/RHSA-2026:5606","https://access.redhat.com/errata/RHSA-2026:6618","https://access.redhat.com/errata/RHSA-2026:6630","https://access.redhat.com/errata/RHSA-2026:6737","https://access.redhat.com/errata/RHSA-2026:6738","https://access.redhat.com/errata/RHSA-2026:7329","https://access.redhat.com/errata/RHSA-2026:7335","https://access.redhat.com/errata/RHSA-2026:7477","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/security/cve/CVE-2025-14831","https://bugzilla.redhat.com/show_bug.cgi?id=2423177","https://gitlab.com/gnutls/gnutls/-/issues/1773","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14831","description":"A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs)."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.37"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"< 0:2.28-251.el8_10.37 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.37"],"available":[{"date":"2026-05-26","kind":"first-observed","version":"0:2.28-251.el8_10.37"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"risk":0.34093,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20587","link":"https://access.redhat.com/errata/RHSA-2026:20587"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4046","description":"A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.37"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"< 0:2.28-251.el8_10.37 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.37"],"available":[{"date":"2026-05-26","kind":"first-observed","version":"0:2.28-251.el8_10.37"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"risk":0.34093,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20587","link":"https://access.redhat.com/errata/RHSA-2026:20587"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4046","description":"A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.37"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"< 0:2.28-251.el8_10.37 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.37"],"available":[{"date":"2026-05-26","kind":"first-observed","version":"0:2.28-251.el8_10.37"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"risk":0.34093,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20587","link":"https://access.redhat.com/errata/RHSA-2026:20587"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4046","description":"A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.37"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4046","versionConstraint":"< 0:2.28-251.el8_10.37 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4046","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.37"],"available":[{"date":"2026-05-26","kind":"first-observed","version":"0:2.28-251.el8_10.37"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"risk":0.34093,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20587","link":"https://access.redhat.com/errata/RHSA-2026:20587"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4046","description":"A flaw was found in glibc, the GNU C Library. A remote attacker could exploit this vulnerability by providing specially crafted inputs using the IBM1390 or IBM1399 character sets to the `iconv()` function. This could lead to an assertion failure, causing the application to crash and resulting in a Denial of Service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-4046","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4046","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-4046","date":"2026-10-08","epss":0.00662,"percentile":0.50136}],"urls":["https://inbox.sourceware.org/libc-announce/76814edf-cf7f-47ec-979d-2dce0a2c76bf@gotplt.org/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=33980","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0007;hb=HEAD","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4046","description":"The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application.\n\n\n\nThis vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them."}]},{"artifact":{"id":"15ab448eaed3b129","cpes":["cpe:2.3:a:libarchive:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.3.3-5.el8?arch=x86_64&distro=rhel-8.10&upstream=libarchive-3.3.3-5.el8.src.rpm","type":"rpm","version":"3.3.3-5.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.3.3-6.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5914","versionConstraint":"< 0:3.3.3-6.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libarchive","version":"0:3.3.3-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-5914","fix":{"state":"fixed","versions":["0:3.3.3-6.el8_10"],"available":[{"date":"2025-08-21","kind":"first-observed","version":"0:3.3.3-6.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5914","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5914","date":"2026-10-08","epss":0.00444,"percentile":0.36575}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14135","link":"https://access.redhat.com/errata/RHSA-2025:14135"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5914","description":"A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition."},"relatedVulnerabilities":[{"id":"CVE-2025-5914","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5914","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5914","date":"2026-10-08","epss":0.00444,"percentile":0.36575}],"urls":["https://access.redhat.com/errata/RHSA-2025:14130","https://access.redhat.com/errata/RHSA-2025:14135","https://access.redhat.com/errata/RHSA-2025:14137","https://access.redhat.com/errata/RHSA-2025:14141","https://access.redhat.com/errata/RHSA-2025:14142","https://access.redhat.com/errata/RHSA-2025:14525","https://access.redhat.com/errata/RHSA-2025:14528","https://access.redhat.com/errata/RHSA-2025:14594","https://access.redhat.com/errata/RHSA-2025:14644","https://access.redhat.com/errata/RHSA-2025:14808","https://access.redhat.com/errata/RHSA-2025:14810","https://access.redhat.com/errata/RHSA-2025:14828","https://access.redhat.com/errata/RHSA-2025:15024","https://access.redhat.com/errata/RHSA-2025:15397","https://access.redhat.com/errata/RHSA-2025:15709","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:16524","https://access.redhat.com/errata/RHSA-2025:18217","https://access.redhat.com/errata/RHSA-2025:18218","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:19041","https://access.redhat.com/errata/RHSA-2025:19046","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:21913","https://access.redhat.com/errata/RHSA-2026:0326","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/errata/RHSA-2026:1541","https://access.redhat.com/security/cve/CVE-2025-5914","https://bugzilla.redhat.com/show_bug.cgi?id=2370861","https://github.com/libarchive/libarchive/pull/2598","https://github.com/libarchive/libarchive/releases/tag/v3.8.0","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5914","description":"A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition."}]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.5.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.0.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.5.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.0.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-166.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-34397","versionConstraint":"< 0:2.56.4-166.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-34397","fix":{"state":"fixed","versions":["0:2.56.4-166.el8_10"],"available":[{"date":"2025-07-17","kind":"first-observed","version":"0:2.56.4-166.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N","metrics":{"baseScore":3.8,"impactScore":1.5,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34397","cwe":"CWE-290","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34397","date":"2026-10-08","epss":0.00763,"percentile":0.5399}],"risk":0.33571999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:11327","link":"https://access.redhat.com/errata/RHSA-2025:11327"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-34397","description":"A flaw was found in GNOME GLib. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This issue could lead to the GDBus-based client behaving incorrectly with an application-dependent impact."},"relatedVulnerabilities":[{"id":"CVE-2024-34397","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.2,"impactScore":4.3,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-34397","cwe":"CWE-290","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-34397","date":"2026-10-08","epss":0.00763,"percentile":0.5399}],"urls":["https://gitlab.gnome.org/GNOME/glib/-/issues/3268","https://lists.debian.org/debian-lts-announce/2024/05/msg00008.html","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/","https://security.netapp.com/advisory/ntap-20240531-0008/","https://www.openwall.com/lists/oss-security/2024/05/07/5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IRSFYAE5X23TNRWX7ZWEJOMISLCDSYNS/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCDY3KA7G7D3DRXYTT46K6LFHS2KHWBH/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LL6HSJDXCXMLEIJBYV6CPOR4K2NTCTXW/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UNFJHISR4O6VFOHBFWH5I5WWMG37H63A/","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-613116.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-34397","description":"An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact."}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0966","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0966","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0966","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0966","date":"2026-10-08","epss":0.00582,"percentile":0.46086}],"risk":0.33464999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0966","description":"A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process."},"relatedVulnerabilities":[{"id":"CVE-2026-0966","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0966","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0966","date":"2026-10-08","epss":0.00582,"percentile":0.46086}],"urls":["https://access.redhat.com/errata/RHSA-2026:18160","https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/errata/RHSA-2026:7067","https://access.redhat.com/security/cve/CVE-2026-0966","https://bugzilla.redhat.com/show_bug.cgi?id=2433121","https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0966","description":"A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0966","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0966","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0966","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0966","date":"2026-10-08","epss":0.00582,"percentile":0.46086}],"risk":0.33464999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0966","description":"A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process."},"relatedVulnerabilities":[{"id":"CVE-2026-0966","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0966","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0966","date":"2026-10-08","epss":0.00582,"percentile":0.46086}],"urls":["https://access.redhat.com/errata/RHSA-2026:18160","https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/errata/RHSA-2026:7067","https://access.redhat.com/security/cve/CVE-2026-0966","https://bugzilla.redhat.com/show_bug.cgi?id=2433121","https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0966","description":"A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful exploitation could lead to a self-Denial of Service of the per-connection daemon process."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.33462000000000003,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19445","description":"A flaw was found in Python. A remote, unauthenticated TLS client can cause a use-after-free in a server that uses SSLContext.sni_callback to assign a different SSLSocket.context when selecting a certificate per server name, if nothing else keeps the original SSLContext alive. This can crash the server process or result in a call through a freed pointer. Servers that wrap their listening socket with a long-lived SSLContext are not affected. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.33462000000000003,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19445","description":"A flaw was found in Python. A remote, unauthenticated TLS client can cause a use-after-free in a server that uses SSLContext.sni_callback to assign a different SSLSocket.context when selecting a certificate per server name, if nothing else keeps the original SSLContext alive. This can crash the server process or result in a call through a freed pointer. Servers that wrap their listening socket with a long-lived SSLContext are not affected. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-169.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-14512","versionConstraint":"< 0:2.56.4-169.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-14512","fix":{"state":"fixed","versions":["0:2.56.4-169.el8_10"],"available":[{"date":"2026-05-12","kind":"first-observed","version":"0:2.56.4-169.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14512","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14512","date":"2026-10-08","epss":0.00579,"percentile":0.45914}],"risk":0.33292499999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:15953","link":"https://access.redhat.com/errata/RHSA-2026:15953"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14512","description":"A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values."},"relatedVulnerabilities":[{"id":"CVE-2025-14512","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14512","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-14512","date":"2026-10-08","epss":0.00579,"percentile":0.45914}],"urls":["https://access.redhat.com/errata/RHSA-2026:15953","https://access.redhat.com/errata/RHSA-2026:15969","https://access.redhat.com/errata/RHSA-2026:15971","https://access.redhat.com/errata/RHSA-2026:19148","https://access.redhat.com/errata/RHSA-2026:19361","https://access.redhat.com/errata/RHSA-2026:19452","https://access.redhat.com/errata/RHSA-2026:19457","https://access.redhat.com/errata/RHSA-2026:19459","https://access.redhat.com/errata/RHSA-2026:19460","https://access.redhat.com/errata/RHSA-2026:19523","https://access.redhat.com/errata/RHSA-2026:19524","https://access.redhat.com/errata/RHSA-2026:19565","https://access.redhat.com/errata/RHSA-2026:19567","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:22634","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2025-14512","https://bugzilla.redhat.com/show_bug.cgi?id=2421339","https://gitlab.gnome.org/GNOME/glib/-/issues/3845"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14512","description":"A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values."}]},{"artifact":{"id":"8d28acbe9944600a","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-base:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_base:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:rpm/redhat/ncurses-base@6.1-10.20180224.el8?arch=noarch&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19211","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-19211","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-08","epss":0.00863,"percentile":0.57341}],"risk":0.332255,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-19211","description":"A vulnerability was found in GNU ncurses due to a NULL pointer dereference in the _nc_parse_entry function within parse_entry.c, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a crash and causing a denial of service condition."},"relatedVulnerabilities":[{"id":"CVE-2018-19211","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-08","epss":0.00863,"percentile":0.57341}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643754"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19211","description":"In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection."}]},{"artifact":{"id":"740497c732ce2972","cpes":["cpe:2.3:a:ncurses-libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_libs:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses-libs:6.1-10.20180224.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:ncurses_libs:6.1-10.20180224.el8:*:*:*:*:*:*:*"],"name":"ncurses-libs","purl":"pkg:rpm/redhat/ncurses-libs@6.1-10.20180224.el8?arch=x86_64&distro=rhel-8.10&upstream=ncurses-6.1-10.20180224.el8.src.rpm","type":"rpm","version":"6.1-10.20180224.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"ncurses","version":"6.1-10.20180224.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-19211","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"ncurses","version":"6.1-10.20180224.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2018-19211","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-08","epss":0.00863,"percentile":0.57341}],"risk":0.332255,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2018-19211","description":"A vulnerability was found in GNU ncurses due to a NULL pointer dereference in the _nc_parse_entry function within parse_entry.c, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a crash and causing a denial of service condition."},"relatedVulnerabilities":[{"id":"CVE-2018-19211","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-19211","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-19211","date":"2026-10-08","epss":0.00863,"percentile":0.57341}],"urls":["https://bugzilla.redhat.com/show_bug.cgi?id=1643754"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-19211","description":"In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a \"dubious character `*' in name or alias field\" detection."}]},{"artifact":{"id":"7e578f402c17b4d5","cpes":["cpe:2.3:a:libsolv:libsolv:0.7.20-6.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libsolv:0.7.20-6.el8:*:*:*:*:*:*:*"],"name":"libsolv","purl":"pkg:rpm/redhat/libsolv@0.7.20-6.el8?arch=x86_64&distro=rhel-8.10&upstream=libsolv-0.7.20-6.el8.src.rpm","type":"rpm","version":"0.7.20-6.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9149","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libsolv","version":"0:0.7.20-6.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-9149","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9149","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-9149","date":"2026-10-08","epss":0.00568,"percentile":0.45338}],"risk":0.3266,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-9149","description":"A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS)."},"relatedVulnerabilities":[{"id":"CVE-2026-9149","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9149","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-9149","date":"2026-10-08","epss":0.00568,"percentile":0.45338}],"urls":["https://access.redhat.com/errata/RHSA-2026:21333","https://access.redhat.com/errata/RHSA-2026:28236","https://access.redhat.com/errata/RHSA-2026:48818","https://access.redhat.com/security/cve/CVE-2026-9149","https://bugzilla.redhat.com/show_bug.cgi?id=2460380","https://github.com/openSUSE/libsolv/pull/617"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9149","description":"A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS)."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54874","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-54874","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"risk":0.32655,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54874","description":"A flaw was found in OpenSSL. Receiving a DTLS (Datagram Transport Layer Security) record for a future epoch while a handshake is in progress causes OpenSSL to buffer an excessive amount of memory. This allows a peer to cause memory exhaustion, eventually resulting in a denial of service, using a small amount of network traffic."},"relatedVulnerabilities":[{"id":"CVE-2026-54874","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54874","cwe":"CWE-405","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54874","date":"2026-10-08","epss":0.00622,"percentile":0.48184}],"urls":["https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23","https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40","https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382","https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107","https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54874","description":"Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell"}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-17.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-59844","versionConstraint":"< 0:0.9.6-17.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-59844","fix":{"state":"fixed","versions":["0:0.9.6-17.el8_10"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0:0.9.6-17.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59844","cwe":"CWE-789","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59844","date":"2026-10-08","epss":0.00567,"percentile":0.45263}],"risk":0.32602499999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:62218","link":"https://access.redhat.com/errata/RHSA-2026:62218"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59844","description":"A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests."},"relatedVulnerabilities":[{"id":"CVE-2026-59844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59844","cwe":"CWE-789","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59844","date":"2026-10-08","epss":0.00567,"percentile":0.45263}],"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59844","https://bugzilla.redhat.com/show_bug.cgi?id=2498177"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59844","description":"A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-17.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59844","versionConstraint":"< 0:0.9.6-17.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-59844","fix":{"state":"fixed","versions":["0:0.9.6-17.el8_10"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0:0.9.6-17.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59844","cwe":"CWE-789","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59844","date":"2026-10-08","epss":0.00567,"percentile":0.45263}],"risk":0.32602499999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:62218","link":"https://access.redhat.com/errata/RHSA-2026:62218"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-59844","description":"A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests."},"relatedVulnerabilities":[{"id":"CVE-2026-59844","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59844","cwe":"CWE-789","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-59844","date":"2026-10-08","epss":0.00567,"percentile":0.45263}],"urls":["https://access.redhat.com/errata/RHSA-2026:42922","https://access.redhat.com/errata/RHSA-2026:55855","https://access.redhat.com/errata/RHSA-2026:62217","https://access.redhat.com/errata/RHSA-2026:62218","https://access.redhat.com/security/cve/CVE-2026-59844","https://bugzilla.redhat.com/show_bug.cgi?id=2498177"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59844","description":"A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-21.el8_10.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-7425","versionConstraint":"< 0:2.9.7-21.el8_10.2 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-7425","fix":{"state":"fixed","versions":["0:2.9.7-21.el8_10.2"],"available":[{"date":"2025-08-01","kind":"first-observed","version":"0:2.9.7-21.el8_10.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7425","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7425","date":"2026-10-08","epss":0.00424,"percentile":0.34716}],"risk":0.32436000000000004,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:12450","link":"https://access.redhat.com/errata/RHSA-2025:12450"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-7425","description":"A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption."},"relatedVulnerabilities":[{"id":"CVE-2025-7425","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-7425","cwe":"CWE-416","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-7425","date":"2026-10-08","epss":0.00424,"percentile":0.34716}],"urls":["https://access.redhat.com/errata/RHBA-2025:12345","https://access.redhat.com/errata/RHSA-2025:12447","https://access.redhat.com/errata/RHSA-2025:12450","https://access.redhat.com/errata/RHSA-2025:13267","https://access.redhat.com/errata/RHSA-2025:13308","https://access.redhat.com/errata/RHSA-2025:13309","https://access.redhat.com/errata/RHSA-2025:13310","https://access.redhat.com/errata/RHSA-2025:13311","https://access.redhat.com/errata/RHSA-2025:13312","https://access.redhat.com/errata/RHSA-2025:13313","https://access.redhat.com/errata/RHSA-2025:13314","https://access.redhat.com/errata/RHSA-2025:13335","https://access.redhat.com/errata/RHSA-2025:13464","https://access.redhat.com/errata/RHSA-2025:13622","https://access.redhat.com/errata/RHSA-2025:14059","https://access.redhat.com/errata/RHSA-2025:14396","https://access.redhat.com/errata/RHSA-2025:14818","https://access.redhat.com/errata/RHSA-2025:14819","https://access.redhat.com/errata/RHSA-2025:14853","https://access.redhat.com/errata/RHSA-2025:14858","https://access.redhat.com/errata/RHSA-2025:15308","https://access.redhat.com/errata/RHSA-2025:15672","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/errata/RHSA-2025:21913","https://access.redhat.com/errata/RHSA-2026:0934","https://access.redhat.com/errata/RHSA-2026:11503","https://access.redhat.com/security/cve/CVE-2025-7425","https://bugzilla.redhat.com/show_bug.cgi?id=2379274","https://gitlab.gnome.org/GNOME/libxslt/-/issues/140","http://seclists.org/fulldisclosure/2025/Aug/0","http://seclists.org/fulldisclosure/2025/Jul/30","http://seclists.org/fulldisclosure/2025/Jul/32","http://seclists.org/fulldisclosure/2025/Jul/35","http://seclists.org/fulldisclosure/2025/Jul/37","http://www.openwall.com/lists/oss-security/2025/07/11/2","https://lists.debian.org/debian-lts-announce/2025/09/msg00035.html","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html","https://cert-portal.siemens.com/productcert/html/ssa-577017.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-7425","description":"A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-0397","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-0397","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"risk":0.32399999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-0397","description":"A vulnerability was found in Python. A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time that certificates are loaded into the SSLContext, such as during the TLS handshake with a  configured certificate directory."},"relatedVulnerabilities":[{"id":"CVE-2024-0397","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/17/2","https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d","https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524","https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e","https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286","https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa","https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab","https://github.com/python/cpython/issues/114572","https://github.com/python/cpython/pull/114573","https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250411-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0397","description":"A defect was discovered in the Python “ssl” module where there is a memory\nrace condition with the ssl.SSLContext methods “cert_store_stats()” and\n“get_ca_certs()”. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-0397","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-0397","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"risk":0.32399999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-0397","description":"A vulnerability was found in Python. A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time that certificates are loaded into the SSLContext, such as during the TLS handshake with a  configured certificate directory."},"relatedVulnerabilities":[{"id":"CVE-2024-0397","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/17/2","https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d","https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524","https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e","https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286","https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa","https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab","https://github.com/python/cpython/issues/114572","https://github.com/python/cpython/pull/114573","https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250411-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0397","description":"A defect was discovered in the Python “ssl” module where there is a memory\nrace condition with the ssl.SSLContext methods “cert_store_stats()” and\n“get_ca_certs()”. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-0397","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-0397","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"risk":0.32399999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-0397","description":"A vulnerability was found in Python. A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time that certificates are loaded into the SSLContext, such as during the TLS handshake with a  configured certificate directory."},"relatedVulnerabilities":[{"id":"CVE-2024-0397","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/17/2","https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d","https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524","https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e","https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286","https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa","https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab","https://github.com/python/cpython/issues/114572","https://github.com/python/cpython/pull/114573","https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250411-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0397","description":"A defect was discovered in the Python “ssl” module where there is a memory\nrace condition with the ssl.SSLContext methods “cert_store_stats()” and\n“get_ca_certs()”. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-0397","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-0397","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"risk":0.32399999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-0397","description":"A vulnerability was found in Python. A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time that certificates are loaded into the SSLContext, such as during the TLS handshake with a  configured certificate directory."},"relatedVulnerabilities":[{"id":"CVE-2024-0397","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-0397","cwe":"CWE-362","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-0397","date":"2026-10-08","epss":0.0081,"percentile":0.55628}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/17/2","https://github.com/python/cpython/commit/01c37f1d0714f5822d34063ca7180b595abf589d","https://github.com/python/cpython/commit/29c97287d205bf2f410f4895ebce3f43b5160524","https://github.com/python/cpython/commit/37324b421b72b7bc9934e27aba85d48d4773002e","https://github.com/python/cpython/commit/542f3272f56f31ed04e74c40635a913fbc12d286","https://github.com/python/cpython/commit/b228655c227b2ca298a8ffac44d14ce3d22f6faa","https://github.com/python/cpython/commit/bce693111bff906ccf9281c22371331aaff766ab","https://github.com/python/cpython/issues/114572","https://github.com/python/cpython/pull/114573","https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250411-0006/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-0397","description":"A defect was discovered in the Python “ssl” module where there is a memory\nrace condition with the ssl.SSLContext methods “cert_store_stats()” and\n“get_ca_certs()”. The race condition can be triggered if the methods are\ncalled at the same time as certificates are loaded into the SSLContext,\nsuch as during the TLS handshake with a certificate directory configured.\nThis issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-14524","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-14524","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"risk":0.32299999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14524","description":"A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients."},"relatedVulnerabilities":[{"id":"CVE-2025-14524","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-14524","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-14524","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"risk":0.32299999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-14524","description":"A flaw was found in curl. When an OAuth2 (Open Authorization) bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a different scheme like IMAP, LDAP, POP3, or SMTP, curl might incorrectly pass the bearer token to the new target host. This could lead to information disclosure, where sensitive authentication tokens are exposed to unintended recipients."},"relatedVulnerabilities":[{"id":"CVE-2025-14524","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"risk":0.322905,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0915","description":"A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"risk":0.322905,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0915","description":"A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"risk":0.322905,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0915","description":"A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0915","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0915","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"risk":0.322905,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0915","description":"A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the resolver to gain sensitive data from the affected system."},"relatedVulnerabilities":[{"id":"CVE-2026-0915","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0915","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-0915","date":"2026-10-08","epss":0.00627,"percentile":0.48446}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33802","http://www.openwall.com/lists/oss-security/2026/01/16/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0915","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver."}]},{"artifact":{"id":"15ab448eaed3b129","cpes":["cpe:2.3:a:libarchive:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libarchive:3.3.3-5.el8:*:*:*:*:*:*:*"],"name":"libarchive","purl":"pkg:rpm/redhat/libarchive@3.3.3-5.el8?arch=x86_64&distro=rhel-8.10&upstream=libarchive-3.3.3-5.el8.src.rpm","type":"rpm","version":"3.3.3-5.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-4426","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libarchive","version":"0:3.3.3-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4426","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4426","cwe":"CWE-1335","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4426","date":"2026-10-08","epss":0.0056,"percentile":0.44879}],"risk":0.32199999999999995,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4426","description":"A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition."},"relatedVulnerabilities":[{"id":"CVE-2026-4426","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4426","cwe":"CWE-1335","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-4426","date":"2026-10-08","epss":0.0056,"percentile":0.44879}],"urls":["https://access.redhat.com/errata/RHSA-2026:8944","https://access.redhat.com/security/cve/CVE-2026-4426","https://bugzilla.redhat.com/show_bug.cgi?id=2449010","https://github.com/libarchive/libarchive/pull/2897"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4426","description":"A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential application crashes, resulting in a denial-of-service (DoS) condition."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-27113","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-27113","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-27113","date":"2026-10-08","epss":0.01053,"percentile":0.63313}],"risk":0.321165,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-27113","description":"A flaw was found in libxml2. This vulnerability allows a NULL pointer dereference, leading to a potential crash or denial of service via a crafted XML pattern."},"relatedVulnerabilities":[{"id":"CVE-2025-27113","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-27113","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-27113","date":"2026-10-08","epss":0.01053,"percentile":0.63313}],"urls":["https://gitlab.gnome.org/GNOME/libxml2/-/issues/861","http://seclists.org/fulldisclosure/2025/Apr/10","http://seclists.org/fulldisclosure/2025/Apr/11","http://seclists.org/fulldisclosure/2025/Apr/12","http://seclists.org/fulldisclosure/2025/Apr/13","http://seclists.org/fulldisclosure/2025/Apr/4","http://seclists.org/fulldisclosure/2025/Apr/5","http://seclists.org/fulldisclosure/2025/Apr/8","http://seclists.org/fulldisclosure/2025/Apr/9","https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html","https://security.netapp.com/advisory/ntap-20250306-0004/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-27113","description":"libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-63074","versionConstraint":">= 3.0.0, < 3.0.22||>= 3.4.0, < 3.4.7||>= 3.5.0, < 3.5.8||>= 3.6.0, < 3.6.4||>= 4.0.0, < 4.0.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-63074","fix":{"state":"fixed","versions":["3.0.22","3.4.7","3.5.8","3.6.4","4.0.2"],"available":[{"date":"2026-08-29","kind":"first-observed","version":"3.0.22"},{"date":"2026-08-29","kind":"first-observed","version":"3.4.7"},{"date":"2026-08-29","kind":"first-observed","version":"3.5.8"},{"date":"2026-08-29","kind":"first-observed","version":"3.6.4"},{"date":"2026-08-29","kind":"first-observed","version":"4.0.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63074","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-63074","date":"2026-10-08","epss":0.00588,"percentile":0.46424}],"risk":0.32046,"urls":["https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7","https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f","https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46","https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af","https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63074","description":"Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE."},"relatedVulnerabilities":[]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.10"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2023-2975","versionConstraint":">= 3.0.0, < 3.0.10||>= 3.1.0, < 3.1.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2023-2975","fix":{"state":"fixed","versions":["3.0.10","3.1.2"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"3.0.10"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-2975","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"},{"cve":"CVE-2023-2975","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2023-2975","date":"2026-10-08","epss":0.00622,"percentile":0.48191}],"risk":0.32033,"urls":["https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=00e2f5eea29994d19293ec4e8c8775ba73678598","https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=6a83f0c958811f07e0d11dfc6b5a6a98edfd5bdc","https://www.openssl.org/news/secadv/20230714.txt","http://www.openwall.com/lists/oss-security/2023/07/15/1","http://www.openwall.com/lists/oss-security/2023/07/19/5","https://security.gentoo.org/glsa/202402-08","https://security.netapp.com/advisory/ntap-20230725-0004/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-2975","description":"Issue summary: The AES-SIV cipher implementation contains a bug that causes\nit to ignore empty associated data entries which are unauthenticated as\na consequence.\n\nImpact summary: Applications that use the AES-SIV algorithm and want to\nauthenticate empty data entries as associated data can be misled by removing,\nadding or reordering such empty entries as these are ignored by the OpenSSL\nimplementation. We are currently unaware of any such applications.\n\nThe AES-SIV algorithm allows for authentication of multiple associated\ndata entries along with the encryption. To authenticate empty data the\napplication has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with\nNULL pointer as the output buffer and 0 as the input buffer length.\nThe AES-SIV implementation in OpenSSL just returns success for such a call\ninstead of performing the associated data authentication operation.\nThe empty data thus will not be authenticated.\n\nAs this issue does not affect non-empty associated data authentication and\nwe expect it to be rare for an application to use empty associated data\nentries this is qualified as Low severity issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-28387","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-28387","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"risk":0.31590499999999994,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-28387","description":"A flaw was found in OpenSSL. An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. This vulnerability could lead to data corruption, application crashes, or, in severe cases, arbitrary code execution. This issue is highly specific and uncommon, as it only affects clients using both PKIX-TA(0)/PKIX-EE(1) and DANE-TA(2) certificate usages and communicating with a server publishing a TLSA record set with both types of records."},"relatedVulnerabilities":[{"id":"CVE-2026-28387","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28387","cwe":"CWE-416","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-28387","date":"2026-10-08","epss":0.00943,"percentile":0.59839}],"urls":["https://github.com/openssl/openssl/commit/07e727d304746edb49a98ee8f6ab00256e1f012b","https://github.com/openssl/openssl/commit/258a8f63b26995ba357f4326da00e19e29c6acbe","https://github.com/openssl/openssl/commit/444958deaf450aea819171f97ae69eaedede42c3","https://github.com/openssl/openssl/commit/7a4e08cee62a728d32e60b0de89e6764339df0a7","https://github.com/openssl/openssl/commit/ec03fa050b3346997ed9c5fef3d0e16ad7db8177","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28387","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-166.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-4373","versionConstraint":"< 0:2.56.4-166.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-4373","fix":{"state":"fixed","versions":["0:2.56.4-166.el8_10"],"available":[{"date":"2025-07-17","kind":"first-observed","version":"0:2.56.4-166.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4373","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4373","date":"2026-10-08","epss":0.00636,"percentile":0.48862}],"risk":0.31164000000000003,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:11327","link":"https://access.redhat.com/errata/RHSA-2025:11327"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-4373","description":"A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite."},"relatedVulnerabilities":[{"id":"CVE-2025-4373","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-4373","cwe":"CWE-124","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-4373","date":"2026-10-08","epss":0.00636,"percentile":0.48862}],"urls":["https://access.redhat.com/errata/RHSA-2025:10855","https://access.redhat.com/errata/RHSA-2025:11140","https://access.redhat.com/errata/RHSA-2025:11327","https://access.redhat.com/errata/RHSA-2025:11373","https://access.redhat.com/errata/RHSA-2025:11374","https://access.redhat.com/errata/RHSA-2025:11662","https://access.redhat.com/errata/RHSA-2025:12275","https://access.redhat.com/errata/RHSA-2025:13335","https://access.redhat.com/errata/RHSA-2025:14988","https://access.redhat.com/errata/RHSA-2025:14989","https://access.redhat.com/errata/RHSA-2025:14990","https://access.redhat.com/errata/RHSA-2025:14991","https://access.redhat.com/security/cve/CVE-2025-4373","https://bugzilla.redhat.com/show_bug.cgi?id=2364265","https://gitlab.gnome.org/GNOME/glib/-/issues/3677","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-089022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-4373","description":"A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite."}]},{"artifact":{"id":"3fa5e9a1b5f18fed","cpes":["cpe:2.3:a:redhat:pcre2:10.32-3.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:pcre2:pcre2:10.32-3.el8_6:*:*:*:*:*:*:*"],"name":"pcre2","purl":"pkg:rpm/redhat/pcre2@10.32-3.el8_6?arch=x86_64&distro=rhel-8.10&upstream=pcre2-10.32-3.el8_6.src.rpm","type":"rpm","version":"10.32-3.el8_6","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"pcre2","version":"0:10.32-3.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.30928999999999995,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-86145","description":"A flaw was found in PCRE2. An out-of-bounds write vulnerability exists in the `pcre2_dfa_match` function due to improper size checking when reusing cached workspace blocks. A remote attacker could exploit this by providing a specially crafted regular expression or a recursive pattern in conjunction with a small heap limit. This could lead to data corruption or potentially arbitrary code execution, compromising the integrity and availability of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.23"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-84782","versionConstraint":">= 1.0.2, < 1.0.2zs||>= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["1.0.2zs","1.1.1zj","3.0.23","3.4.8","3.5.9","3.6.5","4.0.3"],"available":[{"date":"2026-10-05","kind":"first-observed","version":"1.0.2zs"},{"date":"2026-10-05","kind":"first-observed","version":"1.1.1zj"},{"date":"2026-10-05","kind":"first-observed","version":"3.0.23"},{"date":"2026-10-05","kind":"first-observed","version":"3.4.8"},{"date":"2026-10-05","kind":"first-observed","version":"3.5.9"},{"date":"2026-10-05","kind":"first-observed","version":"3.6.5"},{"date":"2026-10-05","kind":"first-observed","version":"4.0.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.30615,"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.30524999999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15079","description":"A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15079","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.30524999999999997,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15079","description":"A flaw was found in curl. When performing SSH-based transfers using SCP or SFTP, libcurl could mistakenly connect to hosts not listed in the user-specified knownhosts file. This occurs if the host is present in the libssh global knownhosts file, effectively bypassing the intended host verification. This could allow a remote attacker to connect to an untrusted host, potentially leading to information disclosure or man-in-the-middle attacks."},"relatedVulnerabilities":[{"id":"CVE-2025-15079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."}]},{"artifact":{"id":"7b479e2b1ed0e25e","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.34-5.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=libpng-1.6.34-5.el8.src.rpm","type":"rpm","version":"2:1.6.34-5.el8","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.34-9.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-64720","versionConstraint":"< 2:1.6.34-9.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libpng","version":"2:1.6.34-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-64720","fix":{"state":"fixed","versions":["2:1.6.34-9.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"2:1.6.34-9.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64720","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64720","date":"2026-10-08","epss":0.00417,"percentile":0.33929}],"risk":0.30441,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:0241","link":"https://access.redhat.com/errata/RHSA-2026:0241"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-64720","description":"A buffer overflow flaw has been discovered in libpng. An out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API."},"relatedVulnerabilities":[{"id":"CVE-2025-64720","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-64720","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-64720","date":"2026-10-08","epss":0.00417,"percentile":0.33929}],"urls":["https://github.com/pnggroup/libpng/commit/08da33b4c88cfcd36e5a706558a8d7e0e4773643","https://github.com/pnggroup/libpng/issues/686","https://github.com/pnggroup/libpng/pull/751","https://github.com/pnggroup/libpng/security/advisories/GHSA-hfc7-ph9c-wcww"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-64720","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7168","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-7168","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"risk":0.304365,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7168","description":"A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user."},"relatedVulnerabilities":[{"id":"CVE-2026-7168","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7168","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-7168","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"risk":0.304365,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7168","description":"A flaw was found in libcurl. When a user performs a transfer over an HTTP proxy using Digest authentication and then reuses the same handle for a second transfer with a different proxy host, libcurl incorrectly sends the `Proxy-Authorization` header intended for the first proxy to the second proxy. This could lead to the disclosure of sensitive authentication information to an unintended proxy, potentially allowing an attacker to gain unauthorized access or impersonate the user."},"relatedVulnerabilities":[{"id":"CVE-2026-7168","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`."}]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.5.0-4.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"< 0:2.5.0-4.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"fixed","versions":["0:2.5.0-4.el8_10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"0:2.5.0-4.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.30225,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:72448","link":"https://access.redhat.com/errata/RHSA-2026:72448"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-93990","description":"A flaw was found in Expat. This vulnerability allows a remote attacker to send specially crafted UTF-16 encoded XML data. Due to improper validation of surrogate characters, the parser can be tricked into accepting malformed sequences, which can hide legitimate markup characters. This could enable XML injection attacks, potentially leading to information disclosure or other integrity impacts."},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.298745,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19553","description":"A flaw was found in Python. When establishing secure connections using the SSLContext.wrap_bio() function with hostname checking enabled, the module fails to validate that a target server hostname is supplied. Because of this missing check, certificate hostname verification is silently skipped rather than triggering an error. A remote man-in-the-middle attacker could exploit this defect to spoof trusted endpoints and intercept or tamper with sensitive encrypted traffic."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.298745,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19553","description":"A flaw was found in Python. When establishing secure connections using the SSLContext.wrap_bio() function with hostname checking enabled, the module fails to validate that a target server hostname is supplied. Because of this missing check, certificate hostname verification is silently skipped rather than triggering an error. A remote man-in-the-middle attacker could exploit this defect to spoof trusted endpoints and intercept or tamper with sensitive encrypted traffic."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7383","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-7383","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.5,"impactScore":4.8,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"risk":0.297925,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-7383","description":"A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input."},"relatedVulnerabilities":[{"id":"CVE-2026-7383","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7383","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-7383","date":"2026-10-08","epss":0.00701,"percentile":0.51746}],"urls":["https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6","https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74","https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974","https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083","https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7383","description":"Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11468","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-11468","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"risk":0.296875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-11468","description":"Missing character filtering has been discovered in Python. When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."},"relatedVulnerabilities":[{"id":"CVE-2025-11468","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"urls":["https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094","https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2","https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6","https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66","https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0","https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796","https://github.com/python/cpython/issues/143935","https://github.com/python/cpython/pull/143936","https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11468","description":"When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-11468","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-11468","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"risk":0.296875,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-11468","description":"Missing character filtering has been discovered in Python. When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."},"relatedVulnerabilities":[{"id":"CVE-2025-11468","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11468","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-11468","date":"2026-10-08","epss":0.00625,"percentile":0.48333}],"urls":["https://github.com/python/cpython/commit/003b8315669b9f08b1010a49071f73f15f818094","https://github.com/python/cpython/commit/17d1490aa97bd6b98a42b1a9b324ead84e7fd8a2","https://github.com/python/cpython/commit/61614a5e5056e4f61ced65008d4576f3df34acb6","https://github.com/python/cpython/commit/a76e4cd62dd68e7cbe86e37e6ed988495a646b66","https://github.com/python/cpython/commit/e9970f077240c7c670e8a6fc6662f2b30d3b6ad0","https://github.com/python/cpython/commit/f738386838021c762efea6c9802c82de65e87796","https://github.com/python/cpython/issues/143935","https://github.com/python/cpython/pull/143936","https://mail.python.org/archives/list/security-announce@python.org/thread/FELSEOLBI2QR6YLG6Q7VYF7FWSGQTKLI/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11468","description":"When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.19"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-22796","versionConstraint":">= 1.0.2, < 1.0.2zn||>= 1.1.1, < 1.1.1ze||>= 3.0.0, < 3.0.19||>= 3.3.0, < 3.3.6||>= 3.4.0, < 3.4.4||>= 3.5.0, < 3.5.5||>= 3.6.0, < 3.6.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-22796","fix":{"state":"fixed","versions":["1.0.2zn","1.1.1ze","3.0.19","3.3.6","3.4.4","3.5.5","3.6.1"],"available":[{"date":"2026-02-03","kind":"first-observed","version":"1.0.2zn"},{"date":"2026-02-03","kind":"first-observed","version":"1.1.1ze"},{"date":"2026-02-03","kind":"first-observed","version":"3.0.19"},{"date":"2026-02-03","kind":"first-observed","version":"3.3.6"},{"date":"2026-02-03","kind":"first-observed","version":"3.4.4"},{"date":"2026-02-03","kind":"first-observed","version":"3.5.5"},{"date":"2026-02-03","kind":"first-observed","version":"3.6.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22796","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-22796","date":"2026-10-08","epss":0.00576,"percentile":0.45751}],"risk":0.29664,"urls":["https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4","https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49","https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12","https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e","https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22796","description":"Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"e91578fe83af8db0","cpes":["cpe:2.3:a:xz-libs:xz-libs:5.2.4-4.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:xz-libs:xz_libs:5.2.4-4.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:xz_libs:xz-libs:5.2.4-4.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:xz_libs:xz_libs:5.2.4-4.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:xz-libs:5.2.4-4.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:xz_libs:5.2.4-4.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:xz:xz-libs:5.2.4-4.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:xz:xz_libs:5.2.4-4.el8_6:*:*:*:*:*:*:*"],"name":"xz-libs","purl":"pkg:rpm/redhat/xz-libs@5.2.4-4.el8_6?arch=x86_64&distro=rhel-8.10&upstream=xz-5.2.4-4.el8_6.src.rpm","type":"rpm","version":"5.2.4-4.el8_6","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"xz","version":"5.2.4-4.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-34743","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"xz","version":"5.2.4-4.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-34743","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"risk":0.295095,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-34743","description":"A flaw was found in XZ Utils. When the `lzma_index_decoder()` function processes an empty index, and a subsequent `lzma_index_append()` operation is performed, insufficient memory is allocated. This can lead to a buffer overflow, potentially causing a denial of service (DoS) for affected systems."},"relatedVulnerabilities":[{"id":"CVE-2026-34743","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-34743","cwe":"CWE-122","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-34743","date":"2026-10-08","epss":0.00573,"percentile":0.45591}],"urls":["https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87","https://github.com/tukaani-project/xz/releases/tag/v5.8.3","https://github.com/tukaani-project/xz/security/advisories/GHSA-x872-m794-cxhv","http://www.openwall.com/lists/oss-security/2026/03/31/13","https://lists.debian.org/debian-lts-announce/2026/07/msg00034.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-34743","description":"XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_decoder() was used to decode an Index that contained no Records, the resulting lzma_index was left in a state where where a subsequent lzma_index_append() would allocate too little memory, and a buffer overflow would occur. This issue has been patched in version 5.8.3."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.16-8.el8_10.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42012","versionConstraint":"< 0:3.6.16-8.el8_10.6 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42012","fix":{"state":"fixed","versions":["0:3.6.16-8.el8_10.6"],"available":[{"date":"2026-05-28","kind":"first-observed","version":"0:3.6.16-8.el8_10.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42012","date":"2026-10-08","epss":0.00487,"percentile":0.3999}],"risk":0.294635,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:20611","link":"https://access.redhat.com/errata/RHSA-2026:20611"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42012","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-42012","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42012","cwe":"CWE-295","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-42012","date":"2026-10-08","epss":0.00487,"percentile":0.3999}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20611","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:30849","https://access.redhat.com/errata/RHSA-2026:30850","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:33125","https://access.redhat.com/errata/RHSA-2026:41921","https://access.redhat.com/errata/RHSA-2026:43575","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-42012","https://bugzilla.redhat.com/show_bug.cgi?id=2467441","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42012","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject Alternative Names (SANs). This could cause the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN), potentially allowing the attacker to spoof legitimate services or intercept sensitive information."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.2944,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6429","description":"A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6429","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.2944,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6429","description":"A flaw was found in libcurl. When configured to use a .netrc file for credentials and follow HTTP redirects, libcurl can inadvertently send the password from the initial connection to the redirected host. This sensitive information disclosure occurs when both the original and redirect URLs use clear text HTTP, are performed over the same HTTP proxy, and the same connection is reused. This vulnerability, categorized as an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200), could allow an attacker to obtain user credentials."},"relatedVulnerabilities":[{"id":"CVE-2026-6429","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5545","description":"A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5545","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5545","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"risk":0.29324999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5545","description":"A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connection authenticated with different credentials, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5545","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5545","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5545","cwe":"CWE-613","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5545","date":"2026-10-08","epss":0.0051,"percentile":0.41602}],"urls":["https://curl.se/docs/CVE-2026-5545.html","https://curl.se/docs/CVE-2026-5545.json","https://hackerone.com/reports/3642555"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5545","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1..."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-12781","description":"A flaw was found in the base64 module in the Python standard library. The b64decode, standard_b64decode and urlsafe_b64decode functions will always accept the '+' and '/' characters even when an alternative base64 alphabet is specified via the altchars parameter that excludes them. This input validation bypass allows malformed or unexpected data to pass through decoding filters, potentially causing logical errors or data integrity issues in applications relying on strict character sets."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-12781","description":"A flaw was found in the base64 module in the Python standard library. The b64decode, standard_b64decode and urlsafe_b64decode functions will always accept the '+' and '/' characters even when an alternative base64 alphabet is specified via the altchars parameter that excludes them. This input validation bypass allows malformed or unexpected data to pass through decoding filters, potentially causing logical errors or data integrity issues in applications relying on strict character sets."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"risk":0.29055,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-84782","description":"A flaw was found in OpenSSL. The Datagram Transport Layer Security (DTLS) retransmission mechanism fails to properly handle handshake message writes that are suspended before completion. A remote attacker could exploit this vulnerability during handshake message retransmission, causing OpenSSL to read past the message buffer or overwrite internal state required to resume writing. This issue can result in information disclosure through out-of-bounds memory reads or cause a Denial of Service (DoS) by crashing the process."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-08","epss":0.0039,"percentile":0.31045}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.28938,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8458","description":"A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an application to wrongfully reuse an existing connection to the same server that was authenticated for a different service, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.28938,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8458","description":"A flaw was found in libcurl. A logical error in the connection pooling mechanism may cause libcurl to reuse an authenticated connection for an unintended service. This could allow an application to wrongfully reuse an existing connection to the same server that was authenticated for a different service, potentially leading to unauthorized access or information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"28726da5e507706a","cpes":["cpe:2.3:a:nmap-ncat:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap-ncat:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap_ncat:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap_ncat:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap:nmap-ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*","cpe:2.3:a:nmap:nmap_ncat:2\\:7.92-1.el8:*:*:*:*:*:*:*"],"name":"nmap-ncat","purl":"pkg:rpm/redhat/nmap-ncat@7.92-1.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=nmap-7.92-1.el8.src.rpm","type":"rpm","version":"2:7.92-1.el8","language":"","licenses":["Nmap"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nmap","version":"7.92-1.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72712","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"nmap","version":"7.92-1.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-72712","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72712","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-72712","date":"2026-10-08","epss":0.00499,"percentile":0.40859}],"risk":0.28692499999999993,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-72712","description":"A flaw was found in Nmap. A remote attacker can exploit this denial of service vulnerability by sending a specially crafted packet that includes a zero-length Transmission Control Protocol (TCP) option. This malformed packet forces the application to enter an infinite loop during packet processing, consuming excessive memory and ultimately causing the Nmap application to crash."},"relatedVulnerabilities":[{"id":"CVE-2026-72712","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72712","cwe":"CWE-835","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-72712","date":"2026-10-08","epss":0.00499,"percentile":0.40859}],"urls":["https://github.com/nmap/nmap","https://github.com/nmap/nmap/commit/7ef4ee030a0023fe22616387a000032e1a678b6a","https://github.com/nmap/nmap/issues/3368","https://www.vulncheck.com/advisories/nmap-denial-of-service-via-zero-length-tcp-option-packet"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72712","description":"Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-75.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4519","versionConstraint":"< 0:3.6.8-75.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4519","fix":{"state":"fixed","versions":["0:3.6.8-75.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-75.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4519","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-4519","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4519","date":"2026-10-08","epss":0.00391,"percentile":0.31085}],"risk":0.28543,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:6473","link":"https://access.redhat.com/errata/RHSA-2026:6473"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4519","description":"A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-4519","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4519","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-4519","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4519","date":"2026-10-08","epss":0.00391,"percentile":0.31085}],"urls":["https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd","https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866","https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e","https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1","https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b","https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4","https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76","https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c","https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5","https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48","https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932","https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03","https://github.com/python/cpython/issues/143930","https://github.com/python/cpython/pull/143931","https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/","http://www.openwall.com/lists/oss-security/2026/03/20/1","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10101","https://access.redhat.com/errata/RHSA-2026:10102","https://access.redhat.com/errata/RHSA-2026:10111","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:19019","https://access.redhat.com/errata/RHSA-2026:19064","https://access.redhat.com/errata/RHSA-2026:19175","https://access.redhat.com/errata/RHSA-2026:19176","https://access.redhat.com/errata/RHSA-2026:19177","https://access.redhat.com/errata/RHSA-2026:19216","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:6016","https://access.redhat.com/errata/RHSA-2026:6035","https://access.redhat.com/errata/RHSA-2026:6256","https://access.redhat.com/errata/RHSA-2026:6281","https://access.redhat.com/errata/RHSA-2026:6283","https://access.redhat.com/errata/RHSA-2026:6285","https://access.redhat.com/errata/RHSA-2026:6286","https://access.redhat.com/errata/RHSA-2026:6473","https://access.redhat.com/errata/RHSA-2026:6766","https://access.redhat.com/errata/RHSA-2026:7010","https://access.redhat.com/errata/RHSA-2026:7244","https://access.redhat.com/errata/RHSA-2026:7329","https://access.redhat.com/errata/RHSA-2026:7335","https://access.redhat.com/errata/RHSA-2026:7443","https://access.redhat.com/errata/RHSA-2026:7661","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/errata/RHSA-2026:9042","https://access.redhat.com/errata/RHSA-2026:9260","https://access.redhat.com/errata/RHSA-2026:9261","https://access.redhat.com/errata/RHSA-2026:9262","https://access.redhat.com/errata/RHSA-2026:9289","https://access.redhat.com/errata/RHSA-2026:9354","https://access.redhat.com/errata/RHSA-2026:9386","https://access.redhat.com/errata/RHSA-2026:9387","https://access.redhat.com/errata/RHSA-2026:9591","https://access.redhat.com/errata/RHSA-2026:9614","https://access.redhat.com/errata/RHSA-2026:9621","https://access.redhat.com/errata/RHSA-2026:9705","https://access.redhat.com/errata/RHSA-2026:9745","https://access.redhat.com/security/cve/CVE-2026-4519","https://bugzilla.redhat.com/show_bug.cgi?id=2449649","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4519","description":"The webbrowser.open() API would accept leading dashes in the URL which \ncould be handled as command line options for certain web browsers. New \nbehavior rejects leading dashes. Users are recommended to sanitize URLs \nprior to passing to webbrowser.open()."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-75.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4519","versionConstraint":"< 0:3.6.8-75.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4519","fix":{"state":"fixed","versions":["0:3.6.8-75.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-75.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4519","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-4519","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4519","date":"2026-10-08","epss":0.00391,"percentile":0.31085}],"risk":0.28543,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:6473","link":"https://access.redhat.com/errata/RHSA-2026:6473"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4519","description":"A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system."},"relatedVulnerabilities":[{"id":"CVE-2026-4519","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4519","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-4519","cwe":"CWE-88","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4519","date":"2026-10-08","epss":0.00391,"percentile":0.31085}],"urls":["https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd","https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866","https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e","https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1","https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b","https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4","https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76","https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c","https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5","https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48","https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932","https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03","https://github.com/python/cpython/issues/143930","https://github.com/python/cpython/pull/143931","https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/","http://www.openwall.com/lists/oss-security/2026/03/20/1","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10101","https://access.redhat.com/errata/RHSA-2026:10102","https://access.redhat.com/errata/RHSA-2026:10111","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:13812","https://access.redhat.com/errata/RHSA-2026:16008","https://access.redhat.com/errata/RHSA-2026:16009","https://access.redhat.com/errata/RHSA-2026:16030","https://access.redhat.com/errata/RHSA-2026:16174","https://access.redhat.com/errata/RHSA-2026:19019","https://access.redhat.com/errata/RHSA-2026:19064","https://access.redhat.com/errata/RHSA-2026:19175","https://access.redhat.com/errata/RHSA-2026:19176","https://access.redhat.com/errata/RHSA-2026:19177","https://access.redhat.com/errata/RHSA-2026:19216","https://access.redhat.com/errata/RHSA-2026:19724","https://access.redhat.com/errata/RHSA-2026:19725","https://access.redhat.com/errata/RHSA-2026:21275","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:6016","https://access.redhat.com/errata/RHSA-2026:6035","https://access.redhat.com/errata/RHSA-2026:6256","https://access.redhat.com/errata/RHSA-2026:6281","https://access.redhat.com/errata/RHSA-2026:6283","https://access.redhat.com/errata/RHSA-2026:6285","https://access.redhat.com/errata/RHSA-2026:6286","https://access.redhat.com/errata/RHSA-2026:6473","https://access.redhat.com/errata/RHSA-2026:6766","https://access.redhat.com/errata/RHSA-2026:7010","https://access.redhat.com/errata/RHSA-2026:7244","https://access.redhat.com/errata/RHSA-2026:7329","https://access.redhat.com/errata/RHSA-2026:7335","https://access.redhat.com/errata/RHSA-2026:7443","https://access.redhat.com/errata/RHSA-2026:7661","https://access.redhat.com/errata/RHSA-2026:8746","https://access.redhat.com/errata/RHSA-2026:8747","https://access.redhat.com/errata/RHSA-2026:8748","https://access.redhat.com/errata/RHSA-2026:9042","https://access.redhat.com/errata/RHSA-2026:9260","https://access.redhat.com/errata/RHSA-2026:9261","https://access.redhat.com/errata/RHSA-2026:9262","https://access.redhat.com/errata/RHSA-2026:9289","https://access.redhat.com/errata/RHSA-2026:9354","https://access.redhat.com/errata/RHSA-2026:9386","https://access.redhat.com/errata/RHSA-2026:9387","https://access.redhat.com/errata/RHSA-2026:9591","https://access.redhat.com/errata/RHSA-2026:9614","https://access.redhat.com/errata/RHSA-2026:9621","https://access.redhat.com/errata/RHSA-2026:9705","https://access.redhat.com/errata/RHSA-2026:9745","https://access.redhat.com/security/cve/CVE-2026-4519","https://bugzilla.redhat.com/show_bug.cgi?id=2449649","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4519","description":"The webbrowser.open() API would accept leading dashes in the URL which \ncould be handled as command line options for certain web browsers. New \nbehavior rejects leading dashes. Users are recommended to sanitize URLs \nprior to passing to webbrowser.open()."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-11168","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-11168","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-11168","cwe":"CWE-918","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-11168","date":"2026-10-08","epss":0.00656,"percentile":0.49855}],"risk":0.28536,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-11168","description":"A flaw was found in Python. The `urllib.parse.urlsplit()` and `urlparse()` functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture compliant. This behavior was not conformant to RFC 3986 and was potentially vulnerable to server-side request forgery (SSRF) if a URL is processed by more than one URL parser."},"relatedVulnerabilities":[{"id":"CVE-2024-11168","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-11168","cwe":"CWE-918","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-11168","date":"2026-10-08","epss":0.00656,"percentile":0.49855}],"urls":["https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5","https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e","https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550","https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132","https://github.com/python/cpython/issues/103848","https://github.com/python/cpython/pull/103849","https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250411-0004/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-11168","description":"The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-11168","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-11168","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-11168","cwe":"CWE-918","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-11168","date":"2026-10-08","epss":0.00656,"percentile":0.49855}],"risk":0.28536,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-11168","description":"A flaw was found in Python. The `urllib.parse.urlsplit()` and `urlparse()` functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture compliant. This behavior was not conformant to RFC 3986 and was potentially vulnerable to server-side request forgery (SSRF) if a URL is processed by more than one URL parser."},"relatedVulnerabilities":[{"id":"CVE-2024-11168","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-11168","cwe":"CWE-918","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-11168","date":"2026-10-08","epss":0.00656,"percentile":0.49855}],"urls":["https://github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5","https://github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89e","https://github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550","https://github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132","https://github.com/python/cpython/issues/103848","https://github.com/python/cpython/pull/103849","https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T/","https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","https://security.netapp.com/advisory/ntap-20250411-0004/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-11168","description":"The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3832","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3832","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3832","date":"2026-10-08","epss":0.0085,"percentile":0.56912}],"risk":0.28475,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3832","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust."},"relatedVulnerabilities":[{"id":"CVE-2026-3832","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3832","cwe":"CWE-179","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3832","date":"2026-10-08","epss":0.0085,"percentile":0.56912}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-3832","https://bugzilla.redhat.com/show_bug.cgi?id=2445762","https://gitlab.com/gnutls/gnutls/-/issues/1801"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3832","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust."}]},{"artifact":{"id":"0b18af35df5be7b3","cpes":["cpe:2.3:a:redhat:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:wget:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=rhel-8.10&upstream=wget-1.19.5-12.el8_10.src.rpm","type":"rpm","version":"1.19.5-12.el8_10","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.19.5-16.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58469","versionConstraint":"< 0:1.19.5-16.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"wget","version":"0:1.19.5-12.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58469","fix":{"state":"fixed","versions":["0:1.19.5-16.el8_10"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0:1.19.5-16.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58469","date":"2026-10-08","epss":0.00493,"percentile":0.4041}],"risk":0.283475,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:62144","link":"https://access.redhat.com/errata/RHSA-2026:62144"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58469","description":"A flaw was found in GNU Wget. A malicious server could exploit a heap buffer underread vulnerability by providing a specially crafted Metalink document containing a URL with only whitespace characters. This could lead to memory corruption and abnormal program behavior, potentially causing a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58469","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58469","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58469","date":"2026-10-08","epss":0.00493,"percentile":0.4041}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58469","description":"GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3783","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3783","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-08","epss":0.00525,"percentile":0.42692}],"risk":0.28087500000000004,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3783","description":"A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-08","epss":0.00525,"percentile":0.42692}],"urls":["https://curl.se/docs/CVE-2026-3783.html","https://curl.se/docs/CVE-2026-3783.json","https://hackerone.com/reports/3583983","http://www.openwall.com/lists/oss-security/2026/03/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3783","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3783","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3783","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.7,"impactScore":3.6,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-08","epss":0.00525,"percentile":0.42692}],"risk":0.28087500000000004,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3783","description":"A flaw was found in curl. When an OAuth2 bearer token is used for an HTTP(S) transfer that redirects to a second URL, curl could unintentionally leak the token. This occurs if the second hostname has entries in the `.netrc` file, allowing the bearer token intended for the first host to be sent to the redirected host. This information disclosure could allow an attacker to gain unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3783","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-08","epss":0.00525,"percentile":0.42692}],"urls":["https://curl.se/docs/CVE-2026-3783.html","https://curl.se/docs/CVE-2026-3783.json","https://hackerone.com/reports/3583983","http://www.openwall.com/lists/oss-security/2026/03/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3783","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.16"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2024-13176","versionConstraint":">= 1.0.2, < 1.0.2zl||>= 1.1.1, < 1.1.1zb||>= 3.0.0, < 3.0.16||>= 3.1.0, < 3.1.8||>= 3.2.0, < 3.2.4||>= 3.3.0, < 3.3.3||>= 3.4.0, < 3.4.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2024-13176","fix":{"state":"fixed","versions":["1.0.2zl","1.1.1zb","3.0.16","3.1.8","3.2.4","3.3.3","3.4.1"],"available":[{"date":"2025-09-04","kind":"first-observed","version":"1.0.2zl"},{"date":"2025-09-04","kind":"first-observed","version":"1.1.1zb"},{"date":"2025-09-04","kind":"first-observed","version":"3.0.16"},{"date":"2025-09-04","kind":"first-observed","version":"3.1.8"},{"date":"2025-09-04","kind":"first-observed","version":"3.2.4"},{"date":"2025-09-04","kind":"first-observed","version":"3.3.3"},{"date":"2025-09-04","kind":"first-observed","version":"3.4.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":3.4,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"risk":0.27891499999999997,"urls":["https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844","https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467","https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902","https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65","https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f","https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded","https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86","https://openssl-library.org/news/secadv/20250120.txt","http://www.openwall.com/lists/oss-security/2025/01/20/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html","https://security.netapp.com/advisory/ntap-20250124-0005/","https://security.netapp.com/advisory/ntap-20250418-0010/","https://security.netapp.com/advisory/ntap-20250502-0006/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-13176","description":"Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue."},"relatedVulnerabilities":[]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6069","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6069","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"risk":0.273885,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6069","description":"A denial-of-service (DoS) vulnerability has been discovered in Python's html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser."},"relatedVulnerabilities":[{"id":"CVE-2025-6069","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"urls":["https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949","https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41","https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49","https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5","https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b","https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc","https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15","https://github.com/python/cpython/issues/135462","https://github.com/python/cpython/pull/135464","https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6069","description":"The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6069","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6069","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"risk":0.273885,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6069","description":"A denial-of-service (DoS) vulnerability has been discovered in Python's html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser."},"relatedVulnerabilities":[{"id":"CVE-2025-6069","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"urls":["https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949","https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41","https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49","https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5","https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b","https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc","https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15","https://github.com/python/cpython/issues/135462","https://github.com/python/cpython/pull/135464","https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6069","description":"The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-6069","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6069","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"risk":0.273885,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6069","description":"A denial-of-service (DoS) vulnerability has been discovered in Python's html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser."},"relatedVulnerabilities":[{"id":"CVE-2025-6069","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"urls":["https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949","https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41","https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49","https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5","https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b","https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc","https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15","https://github.com/python/cpython/issues/135462","https://github.com/python/cpython/pull/135464","https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6069","description":"The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6069","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-6069","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"risk":0.273885,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-6069","description":"A denial-of-service (DoS) vulnerability has been discovered in Python's html.parser.HTMLParser class. When processing specially malformed HTML input, the parsing runtime can become quadratic with respect to the input size. This significantly increased processing time can lead to excessive resource consumption, ultimately causing a denial-of-service condition in applications that rely on this parser."},"relatedVulnerabilities":[{"id":"CVE-2025-6069","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6069","cwe":"CWE-1333","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-6069","date":"2026-10-08","epss":0.00589,"percentile":0.46479}],"urls":["https://github.com/python/cpython/commit/4455cbabf991e202185a25a631af206f60bbc949","https://github.com/python/cpython/commit/6eb6c5dbfb528bd07d77b60fd71fd05d81d45c41","https://github.com/python/cpython/commit/8d1b3dfa09135affbbf27fb8babcf3c11415df49","https://github.com/python/cpython/commit/ab0893fd5c579d9cea30841680e6d35fc478afb5","https://github.com/python/cpython/commit/d851f8e258c7328814943e923a7df81bca15df4b","https://github.com/python/cpython/commit/f3c6f882cddc8dc30320d2e73edf019e201394fc","https://github.com/python/cpython/commit/fdc9d214c01cb4588f540cfa03726bbf2a33fc15","https://github.com/python/cpython/issues/135462","https://github.com/python/cpython/pull/135464","https://mail.python.org/archives/list/security-announce@python.org/thread/K5PIYLR6EP3WR7ZOKKYQUWEDNQVUXOYM/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6069","description":"The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.20"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-31789","versionConstraint":">= 3.0.0, < 3.0.20||>= 3.3.0, < 3.3.7||>= 3.4.0, < 3.4.5||>= 3.5.0, < 3.5.6||>= 3.6.0, < 3.6.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-31789","fix":{"state":"fixed","versions":["3.0.20","3.3.7","3.4.5","3.5.6","3.6.2"],"available":[{"date":"2026-04-09","kind":"first-observed","version":"3.0.20"},{"date":"2026-04-09","kind":"first-observed","version":"3.3.7"},{"date":"2026-04-09","kind":"first-observed","version":"3.4.5"},{"date":"2026-04-09","kind":"first-observed","version":"3.5.6"},{"date":"2026-04-09","kind":"first-observed","version":"3.6.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":5.8,"impactScore":4.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-31789","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-31789","date":"2026-10-08","epss":0.00325,"percentile":0.23508}],"risk":0.273,"urls":["https://github.com/openssl/openssl/commit/364f095b80601db632b0def6a33316967f863bde","https://github.com/openssl/openssl/commit/7a9087efd769f362ad9c0e30c7baaa6bbfa65ecf","https://github.com/openssl/openssl/commit/945b935ac66cc7f1a41f1b849c7c25adb5351f49","https://github.com/openssl/openssl/commit/a24216018e1ede8ff01a4ff5afff7dfbd443e2f9","https://github.com/openssl/openssl/commit/a91e537d16d74050dbde50bb0dfb1fe9930f0521","https://openssl-library.org/news/secadv/20260407.txt","https://cert-portal.siemens.com/productcert/html/ssa-032379.html"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-31789","description":"Issue summary: Converting an excessively large OCTET STRING value to\na hexadecimal string leads to a heap buffer overflow on 32 bit platforms.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nan attacker controlled code execution or other undefined behavior.\n\nIf an attacker can supply a crafted X.509 certificate with an excessively\nlarge OCTET STRING value in extensions such as the Subject Key Identifier\n(SKID) or Authority Key Identifier (AKID) which are being converted to hex,\nthe size of the buffer needed for the result is calculated as multiplication\nof the input length by 3. On 32 bit platforms, this multiplication may overflow\nresulting in the allocation of a smaller buffer and a heap buffer overflow.\n\nApplications and services that print or log contents of untrusted X.509\ncertificates are vulnerable to this issue. As the certificates would have\nto have sizes of over 1 Gigabyte, printing or logging such certificates\nis a fairly unlikely operation and only 32 bit platforms are affected,\nthis issue was assigned Low severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.8.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.8.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3784","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3784","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"risk":0.26967499999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3784","description":"A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user."},"relatedVulnerabilities":[{"id":"CVE-2026-3784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3784","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3784","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"risk":0.26967499999999994,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3784","description":"A flaw was found in curl. This vulnerability allows curl to wrongly reuse an existing HTTP proxy connection when performing a CONNECT request to a server, even if the new request uses different authentication credentials for the HTTP proxy. This improper connection reuse could lead to an attacker gaining unauthorized access to resources or information intended for a different user."},"relatedVulnerabilities":[{"id":"CVE-2026-3784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.26882999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19672","description":"A flaw was found in the Python `tarfile` module. This vulnerability allows an attacker to create empty directories outside of the intended extraction destination on POSIX (Portable Operating System Interface) platforms. This occurs when processing a specially crafted archive containing member names that use directory traversal sequences (e.g., `../`) to leave and then re-enter the target directory. While only empty directories are created outside the destination, this can lead to unintended file system modifications."},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.26882999999999996,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-19672","description":"A flaw was found in the Python `tarfile` module. This vulnerability allows an attacker to create empty directories outside of the intended extraction destination on POSIX (Portable Operating System Interface) platforms. This occurs when processing a specially crafted archive containing member names that use directory traversal sequences (e.g., `../`) to leave and then re-enter the target directory. While only empty directories are created outside the destination, this can lead to unintended file system modifications."},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"1b7de6f060208fa3","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xx22-p4ch-683r","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xx22-p4ch-683r","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"risk":0.26795,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r","https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xx22-p4ch-683r","description":"LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-59949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"urls":["https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1","https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59949","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1."}]},{"artifact":{"id":"0d66728c938c60a4","cpes":["cpe:2.3:a:lz4-java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4-java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4_java:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:org.lz4:lz4_java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4-java:1.8.0:*:*:*:*:*:*:*","cpe:2.3:a:lz4:lz4_java:1.8.0:*:*:*:*:*:*:*"],"name":"lz4-java","purl":"pkg:maven/org.lz4/lz4-java@1.8.0","type":"java-archive","version":"1.8.0","language":"java","licenses":[],"metadata":{"pomGroupID":"org.lz4","virtualPath":"/usr/share/java/kafka/lz4-java-1.8.0.jar","manifestName":"","pomArtifactID":"lz4-java","archiveDigests":[{"value":"4b986a99445e49ea5fbf5d149c4b63f6ed6c6780","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/lz4-java-1.8.0.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/lz4-java-1.8.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-xx22-p4ch-683r","versionConstraint":"<=1.8.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.lz4:lz4-java","version":"1.8.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-xx22-p4ch-683r","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"risk":0.26795,"urls":["https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r","https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-xx22-p4ch-683r","description":"LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges"},"relatedVulnerabilities":[{"id":"CVE-2026-59949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59949","cwe":"CWE-476","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59949","date":"2026-10-08","epss":0.00466,"percentile":0.38363}],"urls":["https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da","https://github.com/yawkat/lz4-java/releases/tag/v1.11.1","https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59949","description":"yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15282","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15282","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"risk":0.26705,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15282","description":"Missing newline filtering has been discovered in Python. User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."},"relatedVulnerabilities":[{"id":"CVE-2025-15282","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"urls":["https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0","https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38","https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80","https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47","https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a","https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f","https://github.com/python/cpython/issues/143925","https://github.com/python/cpython/pull/143926","https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15282","description":"User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15282","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15282","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"risk":0.26705,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15282","description":"Missing newline filtering has been discovered in Python. User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."},"relatedVulnerabilities":[{"id":"CVE-2025-15282","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15282","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15282","date":"2026-10-08","epss":0.00545,"percentile":0.43998}],"urls":["https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0","https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38","https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80","https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47","https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a","https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f","https://github.com/python/cpython/issues/143925","https://github.com/python/cpython/pull/143926","https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15282","description":"User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.26695,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1502","description":"A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1502","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-1502","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"risk":0.26695,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-1502","description":"A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields."},"relatedVulnerabilities":[{"id":"CVE-2026-1502","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1502","cwe":"CWE-93","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1502","date":"2026-10-08","epss":0.00562,"percentile":0.45016}],"urls":["https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69","https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53","https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e","https://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd","https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed","https://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec","https://github.com/python/cpython/issues/146211","https://github.com/python/cpython/pull/146212","https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/","http://www.openwall.com/lists/oss-security/2026/04/11/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1502","description":"CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host."}]},{"artifact":{"id":"5ac1b2cdebe690e2","cpes":["cpe:2.3:a:redhat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:expat:expat:2.2.5-17.el8_10:*:*:*:*:*:*:*"],"name":"expat","purl":"pkg:rpm/redhat/expat@2.2.5-17.el8_10?arch=x86_64&distro=rhel-8.10&upstream=expat-2.2.5-17.el8_10.src.rpm","type":"rpm","version":"2.2.5-17.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76641","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"expat","version":"0:2.2.5-17.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-76641","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"risk":0.26475,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-76641","description":"A flaw was found in Expat. Attackers can exploit an out-of-bounds read vulnerability by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. This can lead to memory corruption. Specifically, a mismatch in struct sizes can cause a read past memory boundaries, potentially resulting in a denial of service (DoS) due to a segfault or incorrect handling of XML attributes."},"relatedVulnerabilities":[{"id":"CVE-2026-76641","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76641","cwe":"CWE-125","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76641","date":"2026-10-08","epss":0.00353,"percentile":0.26927}],"urls":["https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf","https://github.com/libexpat/libexpat/pull/1331","https://www.vulncheck.com/advisories/expat-out-of-bounds-read-via-dtdcopy"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76641","description":"Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. A struct size mismatch between ELEMENT_TYPE members causes storeAtts to read the attIndex member past allocated memory boundaries, resulting in failure to normalize whitespace in non-CDATA attributes or a wild pointer dereference causing a segfault. This vulnerability was introduced by the fix for CVE-2026-66046."}]},{"artifact":{"id":"1435e8d59fac6b89","cpes":["cpe:2.3:a:redhat:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.30-9.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=tar-1.30-9.el8.src.rpm","type":"rpm","version":"2:1.30-9.el8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2:1.30-13.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-45582","versionConstraint":"< 2:1.30-13.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"tar","version":"2:1.30-9.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-45582","fix":{"state":"fixed","versions":["2:1.30-13.el8_10"],"available":[{"date":"2026-09-23","kind":"first-observed","version":"2:1.30-13.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-45582","cwe":"CWE-24","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-45582","date":"2026-10-08","epss":0.00489,"percentile":0.40122}],"risk":0.25917,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:70390","link":"https://access.redhat.com/errata/RHSA-2026:70390"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-45582","description":"A flaw was found in GNU Tar. An attacker could exploit this vulnerability by providing two specially crafted TAR archives, if those archives were extracted in the same directory. The first archive contains a symbolic link that points to a critical directory. The second archive, when extracted, uses this symbolic link to overwrite sensitive files on the system, bypassing existing directory traversal protections. This could lead to unauthorized file modification or, in some cases, privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2025-45582","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":2.8,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-45582","cwe":"CWE-24","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-45582","date":"2026-10-08","epss":0.00489,"percentile":0.40122}],"urls":["https://github.com/i900008/vulndb/blob/main/Gnu_tar_vuln.md","https://lists.gnu.org/archive/html/bug-tar/2025-08/msg00012.html","https://www.gnu.org/software/tar/","https://www.gnu.org/software/tar/manual/html_node/Integrity.html","https://www.gnu.org/software/tar/manual/html_node/Security-rules-of-thumb.html","http://www.openwall.com/lists/oss-security/2025/11/01/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-45582","description":"GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a critical file, specified via a relative pathname that begins with the symlink name and ends with that critical file's name. Here, the extraction follows the symlink and overwrites the critical file. This bypasses the protection mechanism of \"Member name contains '..'\" that would occur for a single TAR archive that attempted to specify the critical file via a ../ approach. For example, the first archive can contain \"x -> ../../../../../home/victim/.ssh\" and the second archive can contain x/authorized_keys. This can affect server applications that automatically extract any number of user-supplied TAR archives, and were relying on the blocking of traversal. This can also affect software installation processes in which \"tar xf\" is run more than once (e.g., when installing a package can automatically install two dependencies that are set up as untrusted tarballs instead of official packages). NOTE: the official GNU Tar manual has an otherwise-empty directory for each \"tar xf\" in its Security Rules of Thumb; however, third-party advice leads users to run \"tar xf\" more than once into the same directory."}]},{"artifact":{"id":"f263313d7dd81d64","cpes":["cpe:2.3:a:daniel_holth_\\<dholth_project:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholth_project:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholthproject:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholthproject:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholth_project:wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel-holth-\\<dholth:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel-holth-\\<dholth:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholth:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholth:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholthproject:wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel-holth-\\<dholth:wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:daniel_holth_\\<dholth:wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python-wheel:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python-wheel:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python_wheel:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python_wheel:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python-wheel:wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python_wheel:wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:wheel:python-wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:wheel:python_wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:python:wheel:0.43.0:*:*:*:*:*:*:*","cpe:2.3:a:wheel:wheel:0.43.0:*:*:*:*:*:*:*"],"name":"wheel","purl":"pkg:pypi/wheel@0.43.0","type":"python","version":"0.43.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/wheel-0.43.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/wheel-0.43.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/wheel-0.43.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools/_vendor/wheel-0.43.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"0.46.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8rrh-rw8j-w5fx","versionConstraint":">=0.40.0,<=0.46.1 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"wheel","version":"0.43.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-8rrh-rw8j-w5fx","fix":{"state":"fixed","versions":["0.46.2"],"available":[{"date":"2026-01-23","kind":"first-observed","version":"0.46.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24049","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-24049","cwe":"CWE-732","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-24049","cwe":"CWE-22","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24049","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24049","date":"2026-10-08","epss":0.00355,"percentile":0.27178}],"risk":0.25915,"urls":["https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx","https://nvd.nist.gov/vuln/detail/CVE-2026-24049","https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef","https://github.com/pypa/wheel/releases/tag/0.46.2","https://github.com/pypa/wheel/commit/934fe177ff912c8e03d5ae951d3805e1fd90ba5e"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8rrh-rw8j-w5fx","description":"Wheel Affected by Arbitrary File Permission Modification via Path Traversal in wheel unpack"},"relatedVulnerabilities":[{"id":"CVE-2026-24049","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24049","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-24049","cwe":"CWE-732","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-24049","cwe":"CWE-22","type":"Secondary","source":"nvd@nist.gov"},{"cve":"CVE-2026-24049","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24049","date":"2026-10-08","epss":0.00355,"percentile":0.27178}],"urls":["https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef","https://github.com/pypa/wheel/releases/tag/0.46.2","https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:1504","https://access.redhat.com/errata/RHSA-2026:17599","https://access.redhat.com/errata/RHSA-2026:1902","https://access.redhat.com/errata/RHSA-2026:1939","https://access.redhat.com/errata/RHSA-2026:1942","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:20089","https://access.redhat.com/errata/RHSA-2026:2090","https://access.redhat.com/errata/RHSA-2026:2106","https://access.redhat.com/errata/RHSA-2026:2139","https://access.redhat.com/errata/RHSA-2026:2675","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2694","https://access.redhat.com/errata/RHSA-2026:2695","https://access.redhat.com/errata/RHSA-2026:2710","https://access.redhat.com/errata/RHSA-2026:2754","https://access.redhat.com/errata/RHSA-2026:2762","https://access.redhat.com/errata/RHSA-2026:2823","https://access.redhat.com/errata/RHSA-2026:2865","https://access.redhat.com/errata/RHSA-2026:2866","https://access.redhat.com/errata/RHSA-2026:2900","https://access.redhat.com/errata/RHSA-2026:2925","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3958","https://access.redhat.com/errata/RHSA-2026:3959","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:4185","https://access.redhat.com/errata/RHSA-2026:4215","https://access.redhat.com/errata/RHSA-2026:4271","https://access.redhat.com/errata/RHSA-2026:4942","https://access.redhat.com/errata/RHSA-2026:5119","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:6192","https://access.redhat.com/errata/RHSA-2026:62115","https://access.redhat.com/errata/RHSA-2026:6555","https://access.redhat.com/errata/RHSA-2026:6562","https://access.redhat.com/errata/RHSA-2026:6565","https://access.redhat.com/errata/RHSA-2026:7250","https://access.redhat.com/security/cve/CVE-2026-24049","https://bugzilla.redhat.com/show_bug.cgi?id=2431959","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24049","description":"wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2."}]},{"artifact":{"id":"7b479e2b1ed0e25e","cpes":["cpe:2.3:a:libpng:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libpng:2\\:1.6.34-5.el8:*:*:*:*:*:*:*"],"name":"libpng","purl":"pkg:rpm/redhat/libpng@1.6.34-5.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=libpng-1.6.34-5.el8.src.rpm","type":"rpm","version":"2:1.6.34-5.el8","language":"","licenses":["zlib"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2:1.6.34-9.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-66293","versionConstraint":"< 2:1.6.34-9.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libpng","version":"2:1.6.34-5.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-66293","fix":{"state":"fixed","versions":["2:1.6.34-9.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"2:1.6.34-9.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66293","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66293","date":"2026-10-08","epss":0.00354,"percentile":0.27058}],"risk":0.25842,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:0241","link":"https://access.redhat.com/errata/RHSA-2026:0241"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-66293","description":"An out of bounds read vulnerability has been discovered in libpng. This vulnerability is in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management."},"relatedVulnerabilities":[{"id":"CVE-2025-66293","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66293","cwe":"CWE-125","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66293","date":"2026-10-08","epss":0.00354,"percentile":0.27058}],"urls":["https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1","https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a","https://github.com/pnggroup/libpng/issues/764","https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f","http://www.openwall.com/lists/oss-security/2025/12/03/6","http://www.openwall.com/lists/oss-security/2025/12/03/7","http://www.openwall.com/lists/oss-security/2025/12/03/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66293","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0865","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0865","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0865","cwe":"CWE-74","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0865","date":"2026-10-08","epss":0.00542,"percentile":0.43795}],"risk":0.25745,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0865","description":"Missing newline filtering has been discovered in Python. User-controlled header names and values containing newlines can allow injecting HTTP headers."},"relatedVulnerabilities":[{"id":"CVE-2026-0865","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0865","cwe":"CWE-74","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0865","date":"2026-10-08","epss":0.00542,"percentile":0.43795}],"urls":["https://github.com/python/cpython/commit/22e4d55285cee52bc4dbe061324e5f30bd4dee58","https://github.com/python/cpython/commit/23e3c0ae867cca0130e441e776c9955b9027c510","https://github.com/python/cpython/commit/286e3ac39984fe85a17f4ab39c64d382137aae5f","https://github.com/python/cpython/commit/2f840249550e082dc351743f474ba56da10478d2","https://github.com/python/cpython/commit/4802b96a2cde58570c24c13ef3289490980961c5","https://github.com/python/cpython/commit/66da7bf6fe7b81e3ecc9c0a25bd47d4616c8d1a6","https://github.com/python/cpython/commit/83ecd18779f286d872f68bfce175651e407d9fff","https://github.com/python/cpython/commit/8bb044d29310bb05d15086cdaa8bf64867d61a97","https://github.com/python/cpython/commit/bfba660085767f8c2d582134e9d511a85eda04cf","https://github.com/python/cpython/commit/c592227ffb48679af9845a45dbb0875d975bb219","https://github.com/python/cpython/commit/e4846a93ac07a8ae9aa18203af0dd13d6e7a6995","https://github.com/python/cpython/commit/f7fceed79ca1bceae8dbe5ba5bc8928564da7211","https://github.com/python/cpython/issues/143916","https://github.com/python/cpython/pull/143917","https://mail.python.org/archives/list/security-announce@python.org/thread/BJ6QPHNSHJTS3A7CFV6IBMCAP2DWRVNT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0865","description":"User-controlled header names and values containing newlines can allow injecting HTTP headers."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0865","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0865","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.5,"impactScore":3.6,"exploitabilityScore":1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0865","cwe":"CWE-74","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0865","date":"2026-10-08","epss":0.00542,"percentile":0.43795}],"risk":0.25745,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0865","description":"Missing newline filtering has been discovered in Python. User-controlled header names and values containing newlines can allow injecting HTTP headers."},"relatedVulnerabilities":[{"id":"CVE-2026-0865","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0865","cwe":"CWE-74","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0865","date":"2026-10-08","epss":0.00542,"percentile":0.43795}],"urls":["https://github.com/python/cpython/commit/22e4d55285cee52bc4dbe061324e5f30bd4dee58","https://github.com/python/cpython/commit/23e3c0ae867cca0130e441e776c9955b9027c510","https://github.com/python/cpython/commit/286e3ac39984fe85a17f4ab39c64d382137aae5f","https://github.com/python/cpython/commit/2f840249550e082dc351743f474ba56da10478d2","https://github.com/python/cpython/commit/4802b96a2cde58570c24c13ef3289490980961c5","https://github.com/python/cpython/commit/66da7bf6fe7b81e3ecc9c0a25bd47d4616c8d1a6","https://github.com/python/cpython/commit/83ecd18779f286d872f68bfce175651e407d9fff","https://github.com/python/cpython/commit/8bb044d29310bb05d15086cdaa8bf64867d61a97","https://github.com/python/cpython/commit/bfba660085767f8c2d582134e9d511a85eda04cf","https://github.com/python/cpython/commit/c592227ffb48679af9845a45dbb0875d975bb219","https://github.com/python/cpython/commit/e4846a93ac07a8ae9aa18203af0dd13d6e7a6995","https://github.com/python/cpython/commit/f7fceed79ca1bceae8dbe5ba5bc8928564da7211","https://github.com/python/cpython/issues/143916","https://github.com/python/cpython/pull/143917","https://mail.python.org/archives/list/security-announce@python.org/thread/BJ6QPHNSHJTS3A7CFV6IBMCAP2DWRVNT/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0865","description":"User-controlled header names and values containing newlines can allow injecting HTTP headers."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-22796","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-22796","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22796","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-22796","date":"2026-10-08","epss":0.00576,"percentile":0.45751}],"risk":0.25632000000000005,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-22796","description":"A flaw was found in OpenSSL. This type confusion vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted PKCS#7 data to an application that performs signature verification. The vulnerability occurs because the application accesses an ASN1_TYPE union member without proper type validation, leading to an invalid or NULL pointer dereference and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-22796","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-22796","cwe":"CWE-754","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-22796","date":"2026-10-08","epss":0.00576,"percentile":0.45751}],"urls":["https://github.com/openssl/openssl/commit/2502e7b7d4c0cf4f972a881641fe09edc67aeec4","https://github.com/openssl/openssl/commit/572844beca95068394c916626a6d3a490f831a49","https://github.com/openssl/openssl/commit/7bbca05be55b129651d9df4bdb92becc45002c12","https://github.com/openssl/openssl/commit/eeee3cbd4d682095ed431052f00403004596373e","https://github.com/openssl/openssl/commit/ef2fb66ec571564d64d1c74a12e388a2a54d05d2","https://openssl-library.org/news/secadv/20260127.txt","https://cert-portal.siemens.com/productcert/html/ssa-265688.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-22796","description":"Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.25531,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15366","description":"A flaw was found in the imaplib module in the Python standard library. The imaplib module does not reject control characters, such as newlines, in user-controlled input passed to IMAP commands. This issue allows an attacker to inject additional commands to be executed in the IMAP server."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.25531,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15366","description":"A flaw was found in the imaplib module in the Python standard library. The imaplib module does not reject control characters, such as newlines, in user-controlled input passed to IMAP commands. This issue allows an attacker to inject additional commands to be executed in the IMAP server."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6238","description":"A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6238","description":"A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6238","description":"A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-6238","description":"A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-08","epss":0.00444,"percentile":0.36552}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"ec5af3e5f03b7859","cpes":["cpe:2.3:a:kjd:internationalized_domain_names_in_applications:3.10:*:*:*:*:python:*:*"],"name":"idna","purl":"pkg:pypi/idna@3.10","type":"python","version":"3.10","language":"python","licenses":["BSD-3-Clause"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/idna-3.10.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/idna-3.10.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/idna-3.10.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/idna-3.10.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-65pc-fj4g-8rjx","versionConstraint":"<3.15 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"idna","version":"3.10"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-65pc-fj4g-8rjx","fix":{"state":"fixed","versions":["3.15"],"available":[{"date":"2026-05-19","kind":"first-observed","version":"3.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"risk":0.25363499999999994,"urls":["https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx","https://nvd.nist.gov/vuln/detail/CVE-2026-45409","https://github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2026-215.yaml"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-65pc-fj4g-8rjx","description":"Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix"},"relatedVulnerabilities":[{"id":"CVE-2026-45409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"urls":["https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409","description":"Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application."}]},{"artifact":{"id":"1d1d40d939f8dea2","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"30ebb05b6b0fb071dbfcf713017c4a767a97bb9b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c4c3-7fpv-j4q5","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c4c3-7fpv-j4q5","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"risk":0.250685,"urls":["https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5","https://nvd.nist.gov/vuln/detail/CVE-2026-75595","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c4c3-7fpv-j4q5","description":"Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext"},"relatedVulnerabilities":[{"id":"CVE-2026-75595","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75595","cwe":"CWE-754","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75595","date":"2026-10-08","epss":0.00277,"percentile":0.18503}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-c4c3-7fpv-j4q5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75595","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so a ClientHello whose handshake header spans records can cause an IndexOutOfBoundsException and invoke select(ctx, null). This selects the default SslContext instead of the SNI-specific context. In deployments where per-SNI clientAuth=REQUIRE is the sole mutual TLS gate, the default SslContext uses clientAuth=NONE or clientAuth=OPTIONAL, and no application-layer certificate verification exists, an unauthenticated remote attacker can bypass the protected route's mutual TLS requirement. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-16.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-5372","versionConstraint":"< 0:0.9.6-16.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-5372","fix":{"state":"fixed","versions":["0:0.9.6-16.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:0.9.6-16.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"risk":0.2505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:21977","link":"https://access.redhat.com/errata/RHSA-2025:21977"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."},"relatedVulnerabilities":[{"id":"CVE-2025-5372","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"urls":["https://access.redhat.com/errata/RHSA-2025:21977","https://access.redhat.com/errata/RHSA-2025:23024","https://access.redhat.com/errata/RHSA-2026:20610","https://access.redhat.com/errata/RHSA-2026:24349","https://access.redhat.com/errata/RHSA-2026:25911","https://access.redhat.com/security/cve/CVE-2025-5372","https://bugzilla.redhat.com/show_bug.cgi?id=2369388"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:0.9.6-16.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-5372","versionConstraint":"< 0:0.9.6-16.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-5372","fix":{"state":"fixed","versions":["0:0.9.6-16.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:0.9.6-16.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"risk":0.2505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:21977","link":"https://access.redhat.com/errata/RHSA-2025:21977"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."},"relatedVulnerabilities":[{"id":"CVE-2025-5372","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5372","cwe":"CWE-682","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5372","date":"2026-10-08","epss":0.00501,"percentile":0.40976}],"urls":["https://access.redhat.com/errata/RHSA-2025:21977","https://access.redhat.com/errata/RHSA-2025:23024","https://access.redhat.com/errata/RHSA-2026:20610","https://access.redhat.com/errata/RHSA-2026:24349","https://access.redhat.com/errata/RHSA-2026:25911","https://access.redhat.com/security/cve/CVE-2025-5372","https://bugzilla.redhat.com/show_bug.cgi?id=2369388"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5372","description":"A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability."}]},{"artifact":{"id":"93eed475e569196b","cpes":["cpe:2.3:a:platform-python-pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python-pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"platform-python-pip","purl":"pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-45803","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-45803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45803","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-45803","date":"2026-10-08","epss":0.00544,"percentile":0.43901}],"risk":0.25024,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-45803","description":"A flaw was found in urllib3, an HTTP client library for Python. urllib3 doesn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303, after changing the method in a request from one that could accept a request body such as `POST` to `GET`, as is required by HTTP RFCs. This issue requires a previously trusted service to become compromised in order to have an impact on confidentiality, therefore, the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies; if this is the case, this vulnerability isn't exploitable."},"relatedVulnerabilities":[{"id":"CVE-2023-45803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45803","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-45803","date":"2026-10-08","epss":0.00544,"percentile":0.43901}],"urls":["https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9","https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/","https://www.rfc-editor.org/rfc/rfc9110.html#name-get","https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45803","description":"urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body."}]},{"artifact":{"id":"fa83cdeeda4e9e6a","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-45803","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2023-45803","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45803","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-45803","date":"2026-10-08","epss":0.00544,"percentile":0.43901}],"risk":0.25024,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2023-45803","description":"A flaw was found in urllib3, an HTTP client library for Python. urllib3 doesn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303, after changing the method in a request from one that could accept a request body such as `POST` to `GET`, as is required by HTTP RFCs. This issue requires a previously trusted service to become compromised in order to have an impact on confidentiality, therefore, the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies; if this is the case, this vulnerability isn't exploitable."},"relatedVulnerabilities":[{"id":"CVE-2023-45803","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.2,"impactScore":3.6,"exploitabilityScore":0.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-45803","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-45803","date":"2026-10-08","epss":0.00544,"percentile":0.43901}],"urls":["https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9","https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/","https://www.rfc-editor.org/rfc/rfc9110.html#name-get","https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-45803","description":"urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body."}]},{"artifact":{"id":"2dd3466fcbd5ba1b","cpes":["cpe:2.3:a:jline-builtins:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline-builtins:jline_builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline_builtins:jline_builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jline:jline_builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline-builtins:3.25.1:*:*:*:*:*:*:*","cpe:2.3:a:jline:jline_builtins:3.25.1:*:*:*:*:*:*:*"],"name":"jline-builtins","purl":"pkg:maven/org.jline/jline-builtins@3.25.1","type":"java-archive","version":"3.25.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.jline","virtualPath":"/usr/share/java/kafka/jline-3.25.1.jar:org.jline:jline-builtins","manifestName":"","pomArtifactID":"jline-builtins","archiveDigests":null},"locations":[{"path":"/usr/share/java/kafka/jline-3.25.1.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jline-3.25.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.30.15"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ph9c-7hw9-vhhw","versionConstraint":">=3.0.0,<3.30.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jline:jline-builtins","version":"3.25.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-ph9c-7hw9-vhhw","fix":{"state":"fixed","versions":["3.30.15"],"available":[{"date":"2026-09-24","kind":"first-observed","version":"3.30.15"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77421","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77421","date":"2026-10-08","epss":0.00434,"percentile":0.35636}],"risk":0.24955,"urls":["https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ph9c-7hw9-vhhw","description":"JLine: ReDoS in Nano Editor Regex Search Mode"},"relatedVulnerabilities":[{"id":"CVE-2026-77421","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77421","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77421","date":"2026-10-08","epss":0.00434,"percentile":0.35636}],"urls":["https://github.com/jline/jline3/commit/1d5fc3099e77938b971e197211cad2d4fbb17541","https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae","https://github.com/jline/jline3/pull/2012","https://github.com/jline/jline3/pull/2018","https://github.com/jline/jline3/releases/tag/4.3.1","https://github.com/jline/jline3/releases/tag/jline-3.30.15","https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77421","description":"JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3644","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"risk":0.24856,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3644","description":"A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve  CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."},"relatedVulnerabilities":[{"id":"CVE-2026-3644","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3644","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-3644","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"risk":0.24856,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-3644","description":"A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve  CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."},"relatedVulnerabilities":[{"id":"CVE-2026-3644","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3644","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-3644","cwe":"CWE-116","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3644","date":"2026-10-08","epss":0.00478,"percentile":0.39324}],"urls":["https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330","https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8","https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4","https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd","https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd","https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef","https://github.com/python/cpython/issues/145599","https://github.com/python/cpython/pull/145600","https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3644","description":"The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output()."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.24749999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8932","description":"A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.24749999999999997,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8932","description":"A flaw was found in curl. The libcurl library, used for transferring data with URLs, could improperly reuse existing network connections. This occurred even when changes to mutual Transport Layer Security (mTLS) settings, particularly those for client certificates, should have prevented such reuse. This issue could lead to a security feature bypass, where a client might use a connection with an unintended or weaker security configuration, potentially compromising the integrity or confidentiality of data."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-177.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15588","versionConstraint":"< 0:2.56.4-177.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-15588","fix":{"state":"fixed","versions":["0:2.56.4-177.el8_10"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"0:2.56.4-177.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"risk":0.24668500000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:61766","link":"https://access.redhat.com/errata/RHSA-2026:61766"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."},"relatedVulnerabilities":[{"id":"CVE-2026-15588","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15588","cwe":"CWE-770","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-15588","date":"2026-10-08","epss":0.00479,"percentile":0.39402}],"urls":["https://access.redhat.com/errata/RHSA-2026:39985","https://access.redhat.com/errata/RHSA-2026:40485","https://access.redhat.com/errata/RHSA-2026:42329","https://access.redhat.com/errata/RHSA-2026:55440","https://access.redhat.com/errata/RHSA-2026:57015","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:61766","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:63140","https://access.redhat.com/errata/RHSA-2026:65762","https://access.redhat.com/errata/RHSA-2026:65763","https://access.redhat.com/errata/RHSA-2026:65767","https://access.redhat.com/errata/RHSA-2026:65768","https://access.redhat.com/errata/RHSA-2026:65769","https://access.redhat.com/errata/RHSA-2026:65770","https://access.redhat.com/errata/RHSA-2026:65771","https://access.redhat.com/errata/RHSA-2026:65773","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:73859","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73929","https://access.redhat.com/errata/RHSA-2026:73930","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/errata/RHSA-2026:74677","https://access.redhat.com/errata/RHSA-2026:74678","https://access.redhat.com/errata/RHSA-2026:74679","https://access.redhat.com/errata/RHSA-2026:74681","https://access.redhat.com/errata/RHSA-2026:74683","https://access.redhat.com/errata/RHSA-2026:74685","https://access.redhat.com/errata/RHSA-2026:74687","https://access.redhat.com/errata/RHSA-2026:74688","https://access.redhat.com/errata/RHSA-2026:74771","https://access.redhat.com/errata/RHSA-2026:75652","https://access.redhat.com/errata/RHSA-2026:75654","https://access.redhat.com/errata/RHSA-2026:75655","https://access.redhat.com/errata/RHSA-2026:75657","https://access.redhat.com/errata/RHSA-2026:75658","https://access.redhat.com/errata/RHSA-2026:75659","https://access.redhat.com/errata/RHSA-2026:75660","https://access.redhat.com/errata/RHSA-2026:76042","https://access.redhat.com/security/cve/CVE-2026-15588","https://bugzilla.redhat.com/show_bug.cgi?id=2499675","https://gitlab.gnome.org/GNOME/glib/-/issues/3985"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15588","description":"A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5928","description":"A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5928","description":"A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5928","description":"A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5928","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5928","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5,"impactScore":4.3,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"risk":0.24650000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5928","description":"A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-5928","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5928","cwe":"CWE-127","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5928","date":"2026-10-08","epss":0.00493,"percentile":0.40414}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33998","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5928","description":"Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.\n\nA bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets."}]},{"artifact":{"id":"5aa1877466828f16","cpes":["cpe:2.3:a:redhat:pam:1.3.1-36.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:pam:pam:1.3.1-36.el8_10:*:*:*:*:*:*:*"],"name":"pam","purl":"pkg:rpm/redhat/pam@1.3.1-36.el8_10?arch=x86_64&distro=rhel-8.10&upstream=pam-1.3.1-36.el8_10.src.rpm","type":"rpm","version":"1.3.1-36.el8_10","language":"","licenses":["BSD and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.3.1-40.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"< 0:1.3.1-40.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"pam","version":"0:1.3.1-36.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"fixed","versions":["0:1.3.1-40.el8_10"],"available":[{"date":"2026-08-19","kind":"first-observed","version":"0:1.3.1-40.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"risk":0.245,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:56131","link":"https://access.redhat.com/errata/RHSA-2026:56131"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54411","description":"A flaw was found in Linux-PAM's `pam_userdb` module. This vulnerability, categorized as an Observable Timing Discrepancy (CWE-208), allows a local or network-adjacent attacker to recover plaintext passwords. By repeatedly attempting authentication and measuring response-timing differences during plaintext password comparison, an attacker can deduce the password. This flaw is exploitable when the `pam_userdb` module is configured to store and compare credentials in plaintext, which is not a default setting."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-08","epss":0.005,"percentile":0.40887}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"93eed475e569196b","cpes":["cpe:2.3:a:platform-python-pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python-pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"platform-python-pip","purl":"pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-50181","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-50181","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"risk":0.24411000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-50181","description":"A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration to manipulate request flows and disrupt service. This bypass occurs through improper handling of retry parameters during PoolManager instantiation. This issue can reult in a denial of service or unintended data exposure due to altered request destinations."},"relatedVulnerabilities":[{"id":"CVE-2025-50181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"urls":["https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181","description":"urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"fa83cdeeda4e9e6a","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-50181","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-50181","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"risk":0.24411000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-50181","description":"A flaw was found in urllib3. The `PoolManager` class allows redirects to be disabled by configuring retries in a specific manner, effectively bypassing intended HTTP redirection behavior. A network attacker can leverage this configuration to manipulate request flows and disrupt service. This bypass occurs through improper handling of retry parameters during PoolManager instantiation. This issue can reult in a denial of service or unintended data exposure due to altered request destinations."},"relatedVulnerabilities":[{"id":"CVE-2025-50181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"urls":["https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181","description":"urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"690a68ab4ef32559","cpes":["cpe:2.3:a:python:urllib3:2.4.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.4.0","type":"python","version":"2.4.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pq67-6m6q-mj2v","versionConstraint":"<2.5.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.4.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-pq67-6m6q-mj2v","fix":{"state":"fixed","versions":["2.5.0"],"available":[{"date":"2025-06-19","kind":"first-observed","version":"2.5.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"risk":0.24411000000000002,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v","https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857","https://nvd.nist.gov/vuln/detail/CVE-2025-50181","https://github.com/urllib3/urllib3/releases/tag/2.5.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pq67-6m6q-mj2v","description":"urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation"},"relatedVulnerabilities":[{"id":"CVE-2025-50181","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50181","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50181","date":"2026-10-08","epss":0.00474,"percentile":0.39002}],"urls":["https://github.com/urllib3/urllib3/commit/f05b1329126d5be6de501f9d1e3e36738bc08857","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-pq67-6m6q-mj2v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50181","description":"urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that disable redirects. By default, requests and botocore users are not affected. An application attempting to mitigate SSRF or open redirect vulnerabilities by disabling redirects at the PoolManager level will remain vulnerable. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.15.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"risk":0.243225,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy"},"relatedVulnerabilities":[{"id":"CVE-2026-59888","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.15.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"risk":0.243225,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy"},"relatedVulnerabilities":[{"id":"CVE-2026-59888","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"c7d49258e4dd82db","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"899e5cf01be55fbf094ad72b2edb0c5df99111ee","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-core-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.15.0,<=2.18.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.18.6"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.18.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"e9a07c843cdc0167","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-core-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"b4f588bf070f77b604c645a7d60b71eae2e6ea09","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-core-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-core-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.15.0,<=2.18.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.18.6"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.18.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"690a68ab4ef32559","cpes":["cpe:2.3:a:python:urllib3:2.4.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.4.0","type":"python","version":"2.4.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.7.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qccp-gfcp-xxvc","versionConstraint":">=1.23,<2.7.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.4.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-qccp-gfcp-xxvc","fix":{"state":"fixed","versions":["2.7.0"],"available":[{"date":"2026-05-11","kind":"first-observed","version":"2.7.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44431","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44431","date":"2026-10-08","epss":0.00339,"percentile":0.2526}],"risk":0.2415375,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc","https://nvd.nist.gov/vuln/detail/CVE-2026-44431"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qccp-gfcp-xxvc","description":"urllib3: Sensitive headers forwarded across origins in proxied low-level redirects"},"relatedVulnerabilities":[{"id":"CVE-2026-44431","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44431","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44431","date":"2026-10-08","epss":0.00339,"percentile":0.2526}],"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc","https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431","description":"urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:7.61.1-34.el8_10.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"< 0:7.61.1-34.el8_10.13 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"fixed","versions":["0:7.61.1-34.el8_10.13"],"available":[{"date":"2026-08-21","kind":"first-observed","version":"0:7.61.1-34.el8_10.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:57462","link":"https://access.redhat.com/errata/RHSA-2026:57462"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8286","description":"A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:7.61.1-34.el8_10.13"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"< 0:7.61.1-34.el8_10.13 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"fixed","versions":["0:7.61.1-34.el8_10.13"],"available":[{"date":"2026-08-21","kind":"first-observed","version":"0:7.61.1-34.el8_10.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:57462","link":"https://access.redhat.com/errata/RHSA-2026:57462"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-8286","description":"A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"risk":0.2405,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4360","description":"A flaw was found in the Python `Tarfile.extract()` function. This vulnerability occurs when processing untrusted tar files containing hardlinks, as the `filter` parameter is not correctly enforced. An attacker could exploit this to write files with unintended user or group ownership, potentially leading to unauthorized modifications or privilege issues on the system."},"relatedVulnerabilities":[{"id":"CVE-2026-4360","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"urls":["https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92","https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4360","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-4360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"risk":0.2405,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-4360","description":"A flaw was found in the Python `Tarfile.extract()` function. This vulnerability occurs when processing untrusted tar files containing hardlinks, as the `filter` parameter is not correctly enforced. An attacker could exploit this to write files with unintended user or group ownership, potentially leading to unauthorized modifications or privilege issues on the system."},"relatedVulnerabilities":[{"id":"CVE-2026-4360","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4360","cwe":"CWE-281","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-4360","date":"2026-10-08","epss":0.00481,"percentile":0.39489}],"urls":["https://github.com/python/cpython/commit/0367912be336348b30572f8029cec4a282782d92","https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0","https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301","https://github.com/python/cpython/commit/7ccdbaba2c54250a70d7f25632152df7655a5e0a","https://github.com/python/cpython/commit/cf23b9153181062150d061468b6d24af33fe214f","https://github.com/python/cpython/commit/d2b2f5eacab4dd48446b63340613b05dcbbf0b44","https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e","https://github.com/python/cpython/issues/151987","https://github.com/python/cpython/pull/151988","https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4360","description":"In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function."}]},{"artifact":{"id":"690a68ab4ef32559","cpes":["cpe:2.3:a:python:urllib3:2.4.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.4.0","type":"python","version":"2.4.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.8.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vxq7-64xx-v4gw","versionConstraint":">=1.10.3,<2.8.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.4.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-vxq7-64xx-v4gw","fix":{"state":"fixed","versions":["2.8.0"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.8.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"risk":0.23944000000000001,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw","https://nvd.nist.gov/vuln/detail/CVE-2026-97689","https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vxq7-64xx-v4gw","description":"urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory"},"relatedVulnerabilities":[{"id":"CVE-2026-97689","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"urls":["https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97689","description":"urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"risk":0.23793,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-54873","description":"A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted network packets to a QUIC protocol endpoint. Because the QUIC stack retains memory in packet buffers until the receiving application reads the stream data, an attacker can manipulate data transfers to keep these buffers allocated indefinitely. This behavior leads to excessive memory consumption and can exhaust available system resources."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-08","epss":0.00462,"percentile":0.38098}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-13176","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-13176","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"risk":0.23600500000000002,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-13176","description":"A timing side-channel vulnerability was found in OpenSSL. This vulnerability allows an attacker to recover the private key. However, measuring the timing would require local access to the signing application or a fast network connection with low latency. There is a timing signal of around 300 nanoseconds when the top word of the inverted ECDSA nonce value is zero. This issue can happen with significant probability only for some of the supported elliptic curves. In particular, the NIST P-521 curve is affected."},"relatedVulnerabilities":[{"id":"CVE-2024-13176","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.1,"impactScore":3.4,"exploitabilityScore":0.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-13176","cwe":"CWE-385","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2024-13176","date":"2026-10-08","epss":0.00613,"percentile":0.47736}],"urls":["https://github.com/openssl/openssl/commit/07272b05b04836a762b4baa874958af51d513844","https://github.com/openssl/openssl/commit/2af62e74fb59bc469506bc37eb2990ea408d9467","https://github.com/openssl/openssl/commit/392dcb336405a0c94486aa6655057f59fd3a0902","https://github.com/openssl/openssl/commit/4b1cb94a734a7d4ec363ac0a215a25c181e11f65","https://github.com/openssl/openssl/commit/77c608f4c8857e63e98e66444e2e761c9627916f","https://github.openssl.org/openssl/extended-releases/commit/0d5fd1ab987f7571e2c955d8d8b638fc0fb54ded","https://github.openssl.org/openssl/extended-releases/commit/a2639000db19878d5d89586ae7b725080592ae86","https://openssl-library.org/news/secadv/20250120.txt","http://www.openwall.com/lists/oss-security/2025/01/20/2","https://lists.debian.org/debian-lts-announce/2025/05/msg00028.html","https://security.netapp.com/advisory/ntap-20250124-0005/","https://security.netapp.com/advisory/ntap-20250418-0010/","https://security.netapp.com/advisory/ntap-20250502-0006/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-13176","description":"Issue summary: A timing side-channel which could potentially allow recovering\nthe private key exists in the ECDSA signature computation.\n\nImpact summary: A timing side-channel in ECDSA signature computations\ncould allow recovering the private key by an attacker. However, measuring\nthe timing would require either local access to the signing application or\na very fast network connection with low latency.\n\nThere is a timing signal of around 300 nanoseconds when the top word of\nthe inverted ECDSA nonce value is zero. This can happen with significant\nprobability only for some of the supported elliptic curves. In particular\nthe NIST P-521 curve is affected. To be able to measure this leak, the attacker\nprocess must either be located in the same physical computer or must\nhave a very fast network connection with low latency. For that reason\nthe severity of this vulnerability is Low.\n\nThe FIPS modules in 3.4, 3.3, 3.2, 3.1 and 3.0 are affected by this issue."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.21"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42767","versionConstraint":">= 3.0.0, < 3.0.21||>= 3.4.0, < 3.4.6||>= 3.5.0, < 3.5.7||>= 3.6.0, < 3.6.3||>= 4.0.0, < 4.0.1 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42767","fix":{"state":"fixed","versions":["3.0.21","3.4.6","3.5.7","3.6.3","4.0.1"],"available":[{"date":"2026-06-11","kind":"first-observed","version":"3.0.21"},{"date":"2026-06-11","kind":"first-observed","version":"3.4.6"},{"date":"2026-06-11","kind":"first-observed","version":"3.5.7"},{"date":"2026-06-11","kind":"first-observed","version":"3.6.3"},{"date":"2026-06-11","kind":"first-observed","version":"4.0.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42767","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42767","date":"2026-10-08","epss":0.00426,"percentile":0.34852}],"risk":0.23217000000000004,"urls":["https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046","https://github.com/openssl/openssl/commit/665d5254083affde9982efca7c41dd01cacc8774","https://github.com/openssl/openssl/commit/810b722f772652ad48042bcc7ab07e3414b11d0f","https://github.com/openssl/openssl/commit/b90ff3b1bd33b1c18e6a09936d097c2eddef8873","https://github.com/openssl/openssl/commit/e6f912907fc2ec82a0fd07aae55172c5e5e3d90d","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42767","description":"Issue summary: An attacker-controlled CMP (Certificate Management Protocol)\nserver could trigger a NULL pointer dereference in a CMP client application.\n\nImpact summary: A NULL pointer dereference causes a crash of the\napplication and a Denial of Service.\n\nAn attacker controlling a CMP server (or acting as a man-in-the-middle) could\ncraft a CMP response containing a CRMF (Certificate Request Message Format)\nCertRepMessage with an EncryptedValue structure where the symmAlg field\nhas an algorithm OID but no parameters field. When the OpenSSL CMP client\nprocesses this response, the NULL dereference occurs, causing a crash of\nthe CMP client.\n\nApplications that process untrusted CMP/CRMF messages may be affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"4afeeed91e127737","cpes":["cpe:2.3:a:libgcc:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libgcc:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libgcc","purl":"pkg:rpm/redhat/libgcc@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.230505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"4fd2ded12bcd7931","cpes":["cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libstdc\\+\\+:8.5.0-26.el8_10:*:*:*:*:*:*:*"],"name":"libstdc++","purl":"pkg:rpm/redhat/libstdc%2B%2B@8.5.0-26.el8_10?arch=x86_64&distro=rhel-8.10&upstream=gcc-8.5.0-26.el8_10.src.rpm","type":"rpm","version":"8.5.0-26.el8_10","language":"","licenses":["GPLv3+ and GPLv3+ with exceptions and GPLv2+ with exceptions and LGPLv2+ and BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"gcc","version":"8.5.0-26.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gcc","version":"8.5.0-26.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"risk":0.230505,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-08","epss":0.00363,"percentile":0.2811}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"risk":0.22981,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0672","description":"An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."},"relatedVulnerabilities":[{"id":"CVE-2026-0672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"urls":["https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172","https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440","https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d","https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca","https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70","https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85","https://github.com/python/cpython/issues/143919","https://github.com/python/cpython/pull/143920","https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0672","description":"When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0672","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0672","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.8,"impactScore":3.6,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"risk":0.22981,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0672","description":"An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."},"relatedVulnerabilities":[{"id":"CVE-2026-0672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0672","cwe":"CWE-93","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-0672","date":"2026-10-08","epss":0.00469,"percentile":0.38616}],"urls":["https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172","https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440","https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d","https://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca","https://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70","https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85","https://github.com/python/cpython/issues/143919","https://github.com/python/cpython/pull/143920","https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0672","description":"When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters."}]},{"artifact":{"id":"c77c9a9a20dbb2f9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.0:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.0:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.0","type":"java-archive","version":"2.16.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"3a6b7f8ff7b30d518bbd65678e9c30cd881f19a7","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","layerID":"sha256:a7f6e4f934600c00f8dcdf6e6cb80b52f44c766e7b9383914c6a60df26913f38","accessPath":"/usr/share/java/cp-base-new/jackson-databind-2.16.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.8.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"risk":0.228145,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties"},"relatedVulnerabilities":[{"id":"CVE-2026-54515","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4."}]},{"artifact":{"id":"cac3d3a65ddc179c","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.16.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.16.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2","type":"java-archive","version":"2.16.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"7fda67535b54d74eebf6157682b835c847410932","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/jackson-databind-2.16.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.8.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.16.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"risk":0.228145,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties"},"relatedVulnerabilities":[{"id":"CVE-2026-54515","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4."}]},{"artifact":{"id":"2fd8ac9813678144","cpes":["cpe:2.3:a:sqlite-libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite-libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite_libs:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:redhat:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite-libs:3.26.0-19.el8_9:*:*:*:*:*:*:*","cpe:2.3:a:sqlite:sqlite_libs:3.26.0-19.el8_9:*:*:*:*:*:*:*"],"name":"sqlite-libs","purl":"pkg:rpm/redhat/sqlite-libs@3.26.0-19.el8_9?arch=x86_64&distro=rhel-8.10&upstream=sqlite-3.26.0-19.el8_9.src.rpm","type":"rpm","version":"3.26.0-19.el8_9","language":"","licenses":["Public Domain"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"sqlite","version":"3.26.0-19.el8_9"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.26.0-21.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11822","versionConstraint":"< 0:3.26.0-21.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"sqlite","version":"3.26.0-19.el8_9"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-11822","fix":{"state":"fixed","versions":["0:3.26.0-21.el8_10"],"available":[{"date":"2026-08-26","kind":"first-observed","version":"0:3.26.0-21.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"risk":0.22491,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:58938","link":"https://access.redhat.com/errata/RHSA-2026:58938"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-11822","description":"A flaw was found in SQLite's FTS5 full-text search extension. This vulnerability involves memory corruption, specifically an out-of-bounds read and a heap buffer overflow, which can be triggered by supplying a crafted database with malformed FTS5 page data. When an FTS5 MATCH query is executed against such a database, an attacker can cause process crashes, memory exhaustion, or achieve arbitrary code execution, potentially compromising the system."},"relatedVulnerabilities":[{"id":"CVE-2026-11822","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11822","cwe":"CWE-122","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-11822","date":"2026-10-08","epss":0.00294,"percentile":0.20129}],"urls":["https://sqlite.org/releaselog/3_53_2.html","https://sqlite.org/src/info/061febcf41ca","https://sqlite.org/src/info/4a5ad516ea93","https://www.vulncheck.com/advisories/sqlite-before-memory-corruption-in-fts5-extension"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11822","description":"SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database."}]},{"artifact":{"id":"ec310121cbd5d68c","cpes":["cpe:2.3:a:python:setuptools:71.1.0:*:*:*:*:*:*:*"],"name":"setuptools","purl":"pkg:pypi/setuptools@71.1.0","type":"python","version":"71.1.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/RECORD","annotations":{"evidence":"supporting"}},{"path":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/top_level.txt","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/setuptools-71.1.0.dist-info/top_level.txt","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"83.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h35f-9h28-mq5c","versionConstraint":"<83.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"setuptools","version":"71.1.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-h35f-9h28-mq5c","fix":{"state":"fixed","versions":["83.0.0"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"83.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"risk":0.22477499999999997,"urls":["https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c","https://nvd.nist.gov/vuln/detail/CVE-2026-59890","https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f","https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml","https://github.com/pypa/setuptools/releases/tag/v83.0.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h35f-9h28-mq5c","description":"setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+"},"relatedVulnerabilities":[{"id":"CVE-2026-59890","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"urls":["https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f","https://github.com/pypa/setuptools/releases/tag/v83.0.0","https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59890","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-80489","description":"A flaw was found in glibc. Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding (for example with iconv) can cause the converter to make no progress, hanging the calling application. Some EUC_JISX0213 sequences decode to two code points; if the output buffer has room for only the first, the second is stored in conversion state and returned as E2BIG, but that pending character is never cleared after it is emitted on the next call, so retries loop forever without consuming further input."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-08","epss":0.00412,"percentile":0.33413}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-77117","description":"A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-08","epss":0.00412,"percentile":0.33412}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"ea2df221c70ba8cc","cpes":["cpe:2.3:a:platform-python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"platform-python","purl":"pkg:rpm/redhat/platform-python@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.223245,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15367","description":"A flaw was found in the poplib module in the Python standard library. The poplib module does not reject control characters, such as newlines, in user-controlled input passed to POP3 commands. This issue allows an attacker to inject additional commands to be executed in the POP3 server."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"817c7e2a7607df0c","cpes":["cpe:2.3:a:python3-libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3-libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3_libs:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-libs:3.6.8-69.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_libs:3.6.8-69.el8_10:*:*:*:*:*:*:*"],"name":"python3-libs","purl":"pkg:rpm/redhat/python3-libs@3.6.8-69.el8_10?arch=x86_64&distro=rhel-8.10&upstream=python3-3.6.8-69.el8_10.src.rpm","type":"rpm","version":"3.6.8-69.el8_10","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python3","version":"3.6.8-69.el8_10"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.6.8-73.el8_10"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 0:3.6.8-73.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python3","version":"3.6.8-69.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"fixed","versions":["0:3.6.8-73.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.6.8-73.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.223245,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:2128","link":"https://access.redhat.com/errata/RHSA-2026:2128"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15367","description":"A flaw was found in the poplib module in the Python standard library. The poplib module does not reject control characters, such as newlines, in user-controlled input passed to POP3 commands. This issue allows an attacker to inject additional commands to be executed in the POP3 server."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"1d1d40d939f8dea2","cpes":["cpe:2.3:a:io.netty.handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty.handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty-project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty_project:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty-handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:netty_handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:io.netty:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:handler:handler:4.1.118.Final:*:*:*:*:*:*:*","cpe:2.3:a:netty:handler:4.1.118.Final:*:*:*:*:*:*:*"],"name":"netty-handler","purl":"pkg:maven/io.netty/netty-handler@4.1.118.Final","type":"java-archive","version":"4.1.118.Final","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"io.netty","virtualPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","manifestName":"","pomArtifactID":"netty-handler","archiveDigests":[{"value":"30ebb05b6b0fb071dbfcf713017c4a767a97bb9b","algorithm":"sha1"}]},"locations":[{"path":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/usr/share/java/kafka/netty-handler-4.1.118.Final.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"4.1.137.Final"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-fccg-mwvh-qqg4","versionConstraint":"<=4.1.136.Final (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"io.netty:netty-handler","version":"4.1.118.Final"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-fccg-mwvh-qqg4","fix":{"state":"fixed","versions":["4.1.137.Final"],"available":[{"date":"2026-09-09","kind":"first-observed","version":"4.1.137.Final"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"risk":0.22253,"urls":["https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4","https://nvd.nist.gov/vuln/detail/CVE-2026-75596","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-fccg-mwvh-qqg4","description":"Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-75596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75596","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-75596","date":"2026-10-08","epss":0.00374,"percentile":0.2925}],"urls":["https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7","https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961","https://github.com/netty/netty/pull/17213","https://github.com/netty/netty/pull/17217","https://github.com/netty/netty/releases/tag/netty-4.1.137.Final","https://github.com/netty/netty/releases/tag/netty-4.2.17.Final","https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75596","description":"Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java at io.netty.handler.ssl.SslClientHelloHandler#decode, where handshakeBuffer.clear() and writeBytes() recopy all previously received body bytes for every additional TLS record. An unauthenticated remote peer can advertise a large ClientHello and deliver its body in thousands of tiny records, causing quadratic CPU work on the event loop before the TLS handshake completes and degrading TLS handling for other clients. This issue is fixed in versions 4.1.137.Final and 4.2.17.Final."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"risk":0.222055,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15281","description":"A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"risk":0.222055,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15281","description":"A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"risk":0.222055,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15281","description":"A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.31"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15281","versionConstraint":"< 0:2.28-251.el8_10.31 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-15281","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.31"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.28-251.el8_10.31"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"risk":0.222055,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:4772","link":"https://access.redhat.com/errata/RHSA-2026:4772"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-15281","description":"A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2025-15281","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15281","cwe":"CWE-908","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2025-15281","date":"2026-10-08","epss":0.00499,"percentile":0.40793}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=33814","http://www.openwall.com/lists/oss-security/2026/01/20/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15281","description":"Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process."}]},{"artifact":{"id":"0b18af35df5be7b3","cpes":["cpe:2.3:a:redhat:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:wget:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=rhel-8.10&upstream=wget-1.19.5-12.el8_10.src.rpm","type":"rpm","version":"1.19.5-12.el8_10","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-16599","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"wget","version":"0:1.19.5-12.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-16599","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"risk":0.21562499999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-16599","description":"A flaw was found in wget's FTP OPIE/S-KEY authentication functionality. A malicious FTP server or a network attacker can send a specially crafted OPIE challenge. This challenge contains a sequence number that, when processed by wget, can lead to an excessive number of cryptographic computations. This prolonged computation can cause wget to become unresponsive, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-16599","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"urls":["https://cert.pl/en/posts/2026/08/CVE-2026-16599","https://gitlab.com/gnuwget/wget","https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16599","description":"GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"}]},{"artifact":{"id":"3687ffa65133e055","cpes":["cpe:2.3:a:file-libs:file-libs:5.33-26.el8:*:*:*:*:*:*:*","cpe:2.3:a:file-libs:file_libs:5.33-26.el8:*:*:*:*:*:*:*","cpe:2.3:a:file_libs:file-libs:5.33-26.el8:*:*:*:*:*:*:*","cpe:2.3:a:file_libs:file_libs:5.33-26.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:file-libs:5.33-26.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:file_libs:5.33-26.el8:*:*:*:*:*:*:*","cpe:2.3:a:file:file-libs:5.33-26.el8:*:*:*:*:*:*:*","cpe:2.3:a:file:file_libs:5.33-26.el8:*:*:*:*:*:*:*"],"name":"file-libs","purl":"pkg:rpm/redhat/file-libs@5.33-26.el8?arch=x86_64&distro=rhel-8.10&upstream=file-5.33-26.el8.src.rpm","type":"rpm","version":"5.33-26.el8","language":"","licenses":["BSD"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"file","version":"5.33-26.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-8905","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"file","version":"5.33-26.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2019-8905","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-8905","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8905","date":"2026-10-08","epss":0.00457,"percentile":0.37665}],"risk":0.21479000000000004,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2019-8905","description":"A vulnerability was found in the \"File\" project where a stack-based buffer over-read exists in the do_core_note function within readelf.c of libmagic.a, by using a specially crafted file the attacker could  access sensitive information or cause a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2019-8905","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:P","metrics":{"baseScore":3.6,"impactScore":5,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-8905","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-8905","date":"2026-10-08","epss":0.00457,"percentile":0.37665}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00027.html","http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00053.html","http://www.securityfocus.com/bid/107137","https://bugs.astron.com/view.php?id=63","https://lists.debian.org/debian-lts-announce/2019/02/msg00044.html","https://usn.ubuntu.com/3911-1/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-8905","description":"do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360."}]},{"artifact":{"id":"64b6d9dcf916f5c6","cpes":["cpe:2.3:a:redhat:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc","purl":"pkg:rpm/redhat/glibc@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"0:2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.21473,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5435","description":"A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"019a3ce15199a3e1","cpes":["cpe:2.3:a:glibc-common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_common:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-common:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_common:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-common","purl":"pkg:rpm/redhat/glibc-common@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.21473,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5435","description":"A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"a10378c28ba5163c","cpes":["cpe:2.3:a:glibc-langpack-en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack-en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack_en:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_langpack:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-langpack-en:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_langpack_en:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-langpack-en","purl":"pkg:rpm/redhat/glibc-langpack-en@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.21473,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5435","description":"A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"f17c38e3ac2f67c3","cpes":["cpe:2.3:a:glibc-minimal-langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal-langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal_langpack:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc-minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc_minimal:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:redhat:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc-minimal-langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*","cpe:2.3:a:glibc:glibc_minimal_langpack:2.28-251.el8_10.16:*:*:*:*:*:*:*"],"name":"glibc-minimal-langpack","purl":"pkg:rpm/redhat/glibc-minimal-langpack@2.28-251.el8_10.16?arch=x86_64&distro=rhel-8.10&upstream=glibc-2.28-251.el8_10.16.src.rpm","type":"rpm","version":"2.28-251.el8_10.16","language":"","licenses":["LGPLv2+ and LGPLv2+ with exceptions and GPLv2+ and GPLv2+ with exceptions and BSD and Inner-Net and ISC and Public Domain and GFDL"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"glibc","version":"2.28-251.el8_10.16"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.28-251.el8_10.40"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"< 0:2.28-251.el8_10.40 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glibc","version":"2.28-251.el8_10.16"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"fixed","versions":["0:2.28-251.el8_10.40"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"0:2.28-251.el8_10.40"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"risk":0.21473,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:42733","link":"https://access.redhat.com/errata/RHSA-2026:42733"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5435","description":"A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-08","epss":0.00394,"percentile":0.31497}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"0b18af35df5be7b3","cpes":["cpe:2.3:a:redhat:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:wget:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=rhel-8.10&upstream=wget-1.19.5-12.el8_10.src.rpm","type":"rpm","version":"1.19.5-12.el8_10","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.19.5-16.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58471","versionConstraint":"< 0:1.19.5-16.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"wget","version":"0:1.19.5-12.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58471","fix":{"state":"fixed","versions":["0:1.19.5-16.el8_10"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0:1.19.5-16.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58471","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"risk":0.21255000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:62144","link":"https://access.redhat.com/errata/RHSA-2026:62144"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58471","description":"A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the convert_fname() function. This occurs when processing a server-supplied filename that requires character set conversion, leading to memory corruption due to incorrect buffer reallocation. This can result in a denial of service or other impacts."},"relatedVulnerabilities":[{"id":"CVE-2026-58471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58471","cwe":"CWE-122","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58471","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58471","description":"GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When the output buffer is too small during iconv E2BIG reallocation, the reallocation logic miscalculates the remaining space, leading to a heap buffer overflow that can be exploited via a maliciously crafted server response."}]},{"artifact":{"id":"0b18af35df5be7b3","cpes":["cpe:2.3:a:redhat:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:wget:wget:1.19.5-12.el8_10:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:rpm/redhat/wget@1.19.5-12.el8_10?arch=x86_64&distro=rhel-8.10&upstream=wget-1.19.5-12.el8_10.src.rpm","type":"rpm","version":"1.19.5-12.el8_10","language":"","licenses":["GPLv3+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.19.5-16.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58472","versionConstraint":"< 0:1.19.5-16.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"wget","version":"0:1.19.5-12.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-58472","fix":{"state":"fixed","versions":["0:1.19.5-16.el8_10"],"available":[{"date":"2026-09-02","kind":"first-observed","version":"0:1.19.5-16.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58472","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"risk":0.21255000000000002,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:62144","link":"https://access.redhat.com/errata/RHSA-2026:62144"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-58472","description":"A flaw was found in GNU Wget. A remote attacker can exploit a heap buffer overflow vulnerability in the `html_quote_string()` function by providing a specially crafted HTML attribute. This can lead to memory corruption and potentially result in arbitrary code execution or a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-58472","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":7.1,"impactScore":4.3,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.9,"impactScore":4.3,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58472","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58472","date":"2026-10-08","epss":0.0039,"percentile":0.30936}],"urls":["https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812","https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-html-attribute-encoding"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58472","description":"GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase."}]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42765","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-42765","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"risk":0.21226500000000004,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-42765","description":"A flaw was found in OpenSSL. When an application is configured with specific non-default settings for certificate verification, including both Online Certificate Status Protocol (OCSP) response checking and partial chain verification, a NULL dereference can occur. This vulnerability can be triggered if the certificate chain lacks a self-signed trusted anchor, causing the application to crash. This leads to a Denial of Service (DoS) for the affected application."},"relatedVulnerabilities":[{"id":"CVE-2026-42765","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42765","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42765","date":"2026-10-08","epss":0.00477,"percentile":0.3919}],"urls":["https://github.com/openssl/openssl/commit/14340b7fa1d444615486bc137014b064e64ec334","https://github.com/openssl/openssl/commit/eb345da18ce2216b2f3ade9c2bc23e068487fa97","https://openssl-library.org/news/secadv/20260609.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42765","description":"Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"feac0516619b3824","cpes":["cpe:2.3:a:python39:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39","purl":"pkg:rpm/redhat/python39@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-5642","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"0:3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-5642","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-5642","date":"2026-10-08","epss":0.00744,"percentile":0.53348}],"risk":0.21204,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-5642","description":"A vulnerability was found in Python/CPython that does not disallow configuring an empty list (\"[]\") for SSLContext.set_npn_protocols(), which is an invalid value for the underlying OpenSSL API. This issue results in a buffer over-read when NPN is used. See CVE -2024-5535 for OpenSSL for more information."},"relatedVulnerabilities":[{"id":"CVE-2024-5642","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-5642","date":"2026-10-08","epss":0.00744,"percentile":0.53348}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/28/4","https://github.com/python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e","https://github.com/python/cpython/commit/a2cdbb6e8188ba9ba8b356b28d91bff60e86fe31","https://github.com/python/cpython/issues/121227","https://github.com/python/cpython/pull/23014","https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html","https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ/","https://security.netapp.com/advisory/ntap-20240726-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-5642","description":"CPython 3.9 and earlier doesn't disallow configuring an empty list (\"[]\") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely used and specifying an empty list likely being uncommon in-practice (typically a protocol name would be configured)."}]},{"artifact":{"id":"024d4c1fc71b9ef8","cpes":["cpe:2.3:a:python39-libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39-libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39_libs:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:python39:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39-libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python39_libs:3.9.20-1.module\\+el8.10.0\\+22342\\+478c159e:*:*:*:*:*:*:*"],"name":"python39-libs","purl":"pkg:rpm/redhat/python39-libs@3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e?arch=x86_64&distro=rhel-8.10&upstream=python39-3.9.20-1.module%2Bel8.10.0%2B22342%2B478c159e.src.rpm","type":"rpm","version":"3.9.20-1.module+el8.10.0+22342+478c159e","language":"","licenses":["Python"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":"python39:3.9:8100020240927003152:d47b87a4"},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"}],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-5642","versionConstraint":"< 0:3.9.25-2.module+el8.10.0+23718+1842ae33 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python39","version":"3.9.20-1.module+el8.10.0+22342+478c159e"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2024-5642","fix":{"state":"fixed","versions":["0:3.9.25-2.module+el8.10.0+23718+1842ae33"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:3.9.25-2.module+el8.10.0+23718+1842ae33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.7,"impactScore":1.5,"exploitabilityScore":1.3},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-5642","date":"2026-10-08","epss":0.00744,"percentile":0.53348}],"risk":0.21204,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:23530","link":"https://access.redhat.com/errata/RHSA-2025:23530"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2024-5642","description":"A vulnerability was found in Python/CPython that does not disallow configuring an empty list (\"[]\") for SSLContext.set_npn_protocols(), which is an invalid value for the underlying OpenSSL API. This issue results in a buffer over-read when NPN is used. See CVE -2024-5535 for OpenSSL for more information."},"relatedVulnerabilities":[{"id":"CVE-2024-5642","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-5642","date":"2026-10-08","epss":0.00744,"percentile":0.53348}],"urls":["http://www.openwall.com/lists/oss-security/2024/06/28/4","https://github.com/python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e","https://github.com/python/cpython/commit/a2cdbb6e8188ba9ba8b356b28d91bff60e86fe31","https://github.com/python/cpython/issues/121227","https://github.com/python/cpython/pull/23014","https://jbp.io/2024/06/27/cve-2024-5535-openssl-memory-safety.html","https://mail.python.org/archives/list/security-announce@python.org/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ/","https://security.netapp.com/advisory/ntap-20240726-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-5642","description":"CPython 3.9 and earlier doesn't disallow configuring an empty list (\"[]\") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely used and specifying an empty list likely being uncommon in-practice (typically a protocol name would be configured)."}]},{"artifact":{"id":"2121f8402291f93e","cpes":["cpe:2.3:a:gnutls:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:gnutls:3.6.16-8.el8_10.3:*:*:*:*:*:*:*"],"name":"gnutls","purl":"pkg:rpm/redhat/gnutls@3.6.16-8.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=gnutls-3.6.16-8.el8_10.3.src.rpm","type":"rpm","version":"3.6.16-8.el8_10.3","language":"","licenses":["GPLv3+ and LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5419","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"gnutls","version":"0:3.6.16-8.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5419","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5419","date":"2026-10-08","epss":0.0063,"percentile":0.48546}],"risk":0.21105,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5419","description":"A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure."},"relatedVulnerabilities":[{"id":"CVE-2026-5419","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5419","cwe":"CWE-208","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5419","date":"2026-10-08","epss":0.0063,"percentile":0.48546}],"urls":["https://access.redhat.com/errata/RHSA-2026:13274","https://access.redhat.com/errata/RHSA-2026:20612","https://access.redhat.com/errata/RHSA-2026:20613","https://access.redhat.com/errata/RHSA-2026:26319","https://access.redhat.com/errata/RHSA-2026:26409","https://access.redhat.com/errata/RHSA-2026:29197","https://access.redhat.com/errata/RHSA-2026:30004","https://access.redhat.com/errata/RHSA-2026:32962","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-5419","https://bugzilla.redhat.com/show_bug.cgi?id=2467686","https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-13"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5419","description":"A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerability is a form of information disclosure."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.22"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75803","versionConstraint":">= 3.0.0, < 3.0.22||>= 3.4.0, < 3.4.7||>= 3.5.0, < 3.5.8||>= 3.6.0, < 3.6.4||>= 4.0.0, < 4.0.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75803","fix":{"state":"fixed","versions":["3.0.22","3.4.7","3.5.8","3.6.4","4.0.2"],"available":[{"date":"2026-08-29","kind":"first-observed","version":"3.0.22"},{"date":"2026-08-29","kind":"first-observed","version":"3.4.7"},{"date":"2026-08-29","kind":"first-observed","version":"3.5.8"},{"date":"2026-08-29","kind":"first-observed","version":"3.6.4"},{"date":"2026-08-29","kind":"first-observed","version":"4.0.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75803","cwe":"CWE-354","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75803","date":"2026-10-08","epss":0.00232,"percentile":0.12871}],"risk":0.20996,"urls":["https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b","https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a","https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9","https://openssl-library.org/news/secadv/20260825.txt"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75803","description":"Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module."},"relatedVulnerabilities":[]},{"artifact":{"id":"5aa1877466828f16","cpes":["cpe:2.3:a:redhat:pam:1.3.1-36.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:pam:pam:1.3.1-36.el8_10:*:*:*:*:*:*:*"],"name":"pam","purl":"pkg:rpm/redhat/pam@1.3.1-36.el8_10?arch=x86_64&distro=rhel-8.10&upstream=pam-1.3.1-36.el8_10.src.rpm","type":"rpm","version":"1.3.1-36.el8_10","language":"","licenses":["BSD and GPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:1.3.1-38.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-8941","versionConstraint":"< 0:1.3.1-38.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"pam","version":"0:1.3.1-36.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-8941","fix":{"state":"fixed","versions":["0:1.3.1-38.el8_10"],"available":[{"date":"2025-09-02","kind":"first-observed","version":"0:1.3.1-38.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8941","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-8941","date":"2026-10-08","epss":0.0027,"percentile":0.17572}],"risk":0.20655,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:14557","link":"https://access.redhat.com/errata/RHSA-2025:14557"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-8941","description":"A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a \"complete\" fix for CVE-2025-6020."},"relatedVulnerabilities":[{"id":"CVE-2025-8941","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-8941","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-8941","date":"2026-10-08","epss":0.0027,"percentile":0.17572}],"urls":["https://access.redhat.com/errata/RHSA-2025:14557","https://access.redhat.com/errata/RHSA-2025:15099","https://access.redhat.com/errata/RHSA-2025:15100","https://access.redhat.com/errata/RHSA-2025:15101","https://access.redhat.com/errata/RHSA-2025:15102","https://access.redhat.com/errata/RHSA-2025:15103","https://access.redhat.com/errata/RHSA-2025:15104","https://access.redhat.com/errata/RHSA-2025:15105","https://access.redhat.com/errata/RHSA-2025:15106","https://access.redhat.com/errata/RHSA-2025:15107","https://access.redhat.com/errata/RHSA-2025:15709","https://access.redhat.com/errata/RHSA-2025:15827","https://access.redhat.com/errata/RHSA-2025:15828","https://access.redhat.com/errata/RHSA-2025:16524","https://access.redhat.com/errata/RHSA-2025:17181","https://access.redhat.com/errata/RHSA-2025:18219","https://access.redhat.com/errata/RHSA-2025:21885","https://access.redhat.com/security/cve/CVE-2025-8941","https://bugzilla.redhat.com/show_bug.cgi?id=2388220"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8941","description":"A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a \"complete\" fix for CVE-2025-6020."}]},{"artifact":{"id":"384c3ed063bd3951","cpes":["cpe:2.3:a:libXrender:libXrender:0.9.10-7.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libXrender:0.9.10-7.el8:*:*:*:*:*:*:*"],"name":"libXrender","purl":"pkg:rpm/redhat/libXrender@0.9.10-7.el8?arch=x86_64&distro=rhel-8.10&upstream=libXrender-0.9.10-7.el8.src.rpm","type":"rpm","version":"0.9.10-7.el8","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-88807","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libXrender","version":"0:0.9.10-7.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-88807","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","metrics":{"baseScore":8.3,"impactScore":6.1,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88807","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88807","date":"2026-10-08","epss":0.0026,"percentile":0.16256}],"risk":0.20539999999999997,"urls":[],"severity":"High","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-88807","description":"A flaw was found in libXrender. Malicious X servers can exploit a heap overflow vulnerability in the RenderQueryPictFormats function. This allows them to inject arbitrary code into connected X clients, potentially leading to unauthorized control over the client's system."},"relatedVulnerabilities":[{"id":"CVE-2026-88807","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88807","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88807","date":"2026-10-08","epss":0.0026,"percentile":0.16256}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88807","description":"A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients."}]},{"artifact":{"id":"35ff13ecec739883","cpes":["cpe:2.3:a:redhat:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:glib2:glib2:2.56.4-165.el8_10:*:*:*:*:*:*:*"],"name":"glib2","purl":"pkg:rpm/redhat/glib2@2.56.4-165.el8_10?arch=x86_64&distro=rhel-8.10&upstream=glib2-2.56.4-165.el8_10.src.rpm","type":"rpm","version":"2.56.4-165.el8_10","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.56.4-168.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-13601","versionConstraint":"< 0:2.56.4-168.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"glib2","version":"0:2.56.4-165.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-13601","fix":{"state":"fixed","versions":["0:2.56.4-168.el8_10"],"available":[{"date":"2026-04-22","kind":"first-observed","version":"0:2.56.4-168.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.2,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13601","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-13601","date":"2026-10-08","epss":0.00322,"percentile":0.23253}],"risk":0.20446999999999999,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:0991","link":"https://access.redhat.com/errata/RHSA-2026:0991"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-13601","description":"A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string."},"relatedVulnerabilities":[{"id":"CVE-2025-13601","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.2,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13601","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-13601","date":"2026-10-08","epss":0.00322,"percentile":0.23253}],"urls":["https://access.redhat.com/errata/RHSA-2026:0936","https://access.redhat.com/errata/RHSA-2026:0975","https://access.redhat.com/errata/RHSA-2026:0991","https://access.redhat.com/errata/RHSA-2026:1323","https://access.redhat.com/errata/RHSA-2026:1324","https://access.redhat.com/errata/RHSA-2026:1326","https://access.redhat.com/errata/RHSA-2026:1327","https://access.redhat.com/errata/RHSA-2026:1465","https://access.redhat.com/errata/RHSA-2026:1608","https://access.redhat.com/errata/RHSA-2026:1624","https://access.redhat.com/errata/RHSA-2026:1625","https://access.redhat.com/errata/RHSA-2026:1626","https://access.redhat.com/errata/RHSA-2026:1627","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:18344","https://access.redhat.com/errata/RHSA-2026:18705","https://access.redhat.com/errata/RHSA-2026:2064","https://access.redhat.com/errata/RHSA-2026:2072","https://access.redhat.com/errata/RHSA-2026:2485","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2633","https://access.redhat.com/errata/RHSA-2026:2659","https://access.redhat.com/errata/RHSA-2026:2671","https://access.redhat.com/errata/RHSA-2026:2974","https://access.redhat.com/errata/RHSA-2026:3415","https://access.redhat.com/errata/RHSA-2026:4419","https://access.redhat.com/errata/RHSA-2026:7461","https://access.redhat.com/security/cve/CVE-2025-13601","https://bugzilla.redhat.com/show_bug.cgi?id=2416741","https://gitlab.gnome.org/GNOME/glib/-/issues/3827","https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13601","description":"A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string."}]},{"artifact":{"id":"fa7fdde8004361a1","cpes":["cpe:2.3:a:libssh:libssh:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh","purl":"pkg:rpm/redhat/libssh@0.9.6-14.el8?arch=x86_64&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0964","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0:0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0964","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0964","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0964","date":"2026-10-08","epss":0.00408,"percentile":0.33005}],"risk":0.20400000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0964","description":"A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111."},"relatedVulnerabilities":[{"id":"CVE-2026-0964","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0964","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0964","date":"2026-10-08","epss":0.00408,"percentile":0.33005}],"urls":["https://access.redhat.com/errata/RHSA-2026:18160","https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/security/cve/CVE-2026-0964","https://bugzilla.redhat.com/show_bug.cgi?id=2436979","https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0964","description":"A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111."}]},{"artifact":{"id":"e4227c9ab1d13bba","cpes":["cpe:2.3:a:libssh-config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh-config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh_config:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:libssh:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh-config:0.9.6-14.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libssh_config:0.9.6-14.el8:*:*:*:*:*:*:*"],"name":"libssh-config","purl":"pkg:rpm/redhat/libssh-config@0.9.6-14.el8?arch=noarch&distro=rhel-8.10&upstream=libssh-0.9.6-14.el8.src.rpm","type":"rpm","version":"0.9.6-14.el8","language":"","licenses":["LGPLv2+"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"libssh","version":"0.9.6-14.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0964","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libssh","version":"0.9.6-14.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-0964","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0964","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0964","date":"2026-10-08","epss":0.00408,"percentile":0.33005}],"risk":0.20400000000000001,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-0964","description":"A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111."},"relatedVulnerabilities":[{"id":"CVE-2026-0964","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5,"impactScore":3.4,"exploitabilityScore":1.7},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0964","cwe":"CWE-22","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-0964","date":"2026-10-08","epss":0.00408,"percentile":0.33005}],"urls":["https://access.redhat.com/errata/RHSA-2026:18160","https://access.redhat.com/errata/RHSA-2026:18683","https://access.redhat.com/security/cve/CVE-2026-0964","https://bugzilla.redhat.com/show_bug.cgi?id=2436979","https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0964","description":"A malicious SCP server can send unexpected paths that could make the\nclient application override local files outside of working directory.\nThis could be misused to create malicious executable or configuration\nfiles and make the user execute them under specific consequences.\n\nThis is the same issue as in OpenSSH, tracked as CVE-2019-6111."}]},{"artifact":{"id":"93eed475e569196b","cpes":["cpe:2.3:a:platform-python-pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python-pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python_pip:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform-python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform_python:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:platform:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform-python-pip:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:platform_python_pip:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"platform-python-pip","purl":"pkg:rpm/redhat/platform-python-pip@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-50182","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-50182","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"risk":0.202395,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-50182","description":"A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can enable a remote attacker to control the redirect destination, leading to arbitrary URL redirection. Consequently, an attacker can redirect users to malicious websites. This \nvulnerability stems from a failure to constrain the redirect target."},"relatedVulnerabilities":[{"id":"CVE-2025-50182","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"urls":["https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"fa83cdeeda4e9e6a","cpes":["cpe:2.3:a:python3-pip-wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_wheel:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3-pip-wheel:9.0.3-24.el8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:python3_pip_wheel:9.0.3-24.el8:*:*:*:*:*:*:*"],"name":"python3-pip-wheel","purl":"pkg:rpm/redhat/python3-pip-wheel@9.0.3-24.el8?arch=noarch&distro=rhel-8.10&upstream=python-pip-9.0.3-24.el8.src.rpm","type":"rpm","version":"9.0.3-24.el8","language":"","licenses":["MIT and Python and ASL 2.0 and BSD and ISC and LGPLv2 and MPLv2.0 and (ASL 2.0 or BSD)"],"metadata":{"epoch":null,"architecture":"noarch","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-pip","version":"9.0.3-24.el8"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-50182","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"python-pip","version":"9.0.3-24.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-50182","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"risk":0.202395,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-50182","description":"A flaw was found in urllib3. The library fails to properly validate redirect URLs, allowing an attacker to manipulate redirect chains when used in environments like Pyodide utilizing the JavaScript Fetch API. This lack of validation can enable a remote attacker to control the redirect destination, leading to arbitrary URL redirection. Consequently, an attacker can redirect users to malicious websites. This \nvulnerability stems from a failure to constrain the redirect target."},"relatedVulnerabilities":[{"id":"CVE-2025-50182","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"urls":["https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"690a68ab4ef32559","cpes":["cpe:2.3:a:python:urllib3:2.4.0:*:*:*:*:*:*:*"],"name":"urllib3","purl":"pkg:pypi/urllib3@2.4.0","type":"python","version":"2.4.0","language":"python","licenses":["MIT"],"locations":[{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/lib/python3.9/site-packages/urllib3-2.4.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.5.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-48p4-8xcf-vxj5","versionConstraint":">=2.2.0,<2.5.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"urllib3","version":"2.4.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-48p4-8xcf-vxj5","fix":{"state":"fixed","versions":["2.5.0"],"available":[{"date":"2025-06-19","kind":"first-observed","version":"2.5.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"risk":0.202395,"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5","https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f","https://nvd.nist.gov/vuln/detail/CVE-2025-50182","https://github.com/urllib3/urllib3/releases/tag/2.5.0"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-48p4-8xcf-vxj5","description":"urllib3 does not control redirects in browsers and Node.js"},"relatedVulnerabilities":[{"id":"CVE-2025-50182","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-50182","cwe":"CWE-601","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-50182","date":"2026-10-08","epss":0.00393,"percentile":0.31356}],"urls":["https://github.com/urllib3/urllib3/commit/7eb4a2aafe49a279c29b6d1f0ed0f42e9736194f","https://github.com/urllib3/urllib3/releases/tag/2.5.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-48p4-8xcf-vxj5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-50182","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest. This means Python libraries can be used to make HTTP requests from a browser or Node.js. Additionally, urllib3 provides a mechanism to control redirects, but the retries and redirect parameters are ignored with Pyodide; the runtime itself determines redirect behavior. This issue has been patched in version 2.5.0."}]},{"artifact":{"id":"1435e8d59fac6b89","cpes":["cpe:2.3:a:redhat:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.30-9.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=tar-1.30-9.el8.src.rpm","type":"rpm","version":"2:1.30-9.el8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2:1.30-13.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"< 2:1.30-13.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"tar","version":"2:1.30-9.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"fixed","versions":["2:1.30-13.el8_10"],"available":[{"date":"2026-09-23","kind":"first-observed","version":"2:1.30-13.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2026:70390","link":"https://access.redhat.com/errata/RHSA-2026:70390"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-08","epss":0.00401,"percentile":0.32244}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"7c95ba6a5ab2b738","cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:generic/openssl@3.0.9","type":"binary","version":"3.0.9","language":"","licenses":[],"locations":[{"path":"/usr/local/bin/openssl","layerID":"sha256:1250bd487b1afc09953352e5292832da53b53c662f0307529d122ea423ab65de","accessPath":"/usr/local/bin/openssl","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.0.23"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-75806","versionConstraint":">= 1.1.1, < 1.1.1zj||>= 3.0.0, < 3.0.23||>= 3.4.0, < 3.4.8||>= 3.5.0, < 3.5.9||>= 3.6.0, < 3.6.5||>= 4.0.0, < 4.0.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:openssl:openssl:3.0.9:*:*:*:*:*:*:*"],"package":{"name":"openssl","version":"3.0.9"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["1.1.1zj","3.0.23","3.4.8","3.5.9","3.6.5","4.0.3"],"available":[{"date":"2026-10-05","kind":"first-observed","version":"1.1.1zj"},{"date":"2026-10-05","kind":"first-observed","version":"3.0.23"},{"date":"2026-10-05","kind":"first-observed","version":"3.4.8"},{"date":"2026-10-05","kind":"first-observed","version":"3.5.9"},{"date":"2026-10-05","kind":"first-observed","version":"3.6.5"},{"date":"2026-10-05","kind":"first-observed","version":"4.0.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[]},{"artifact":{"id":"eb99cfff9b3dd79b","cpes":["cpe:2.3:a:openssl-libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl-libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl_libs:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl-libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openssl_libs:1\\:1.1.1k-14.el8_6:*:*:*:*:*:*:*"],"name":"openssl-libs","purl":"pkg:rpm/redhat/openssl-libs@1.1.1k-14.el8_6?arch=x86_64&distro=rhel-8.10&epoch=1&upstream=openssl-1.1.1k-14.el8_6.src.rpm","type":"rpm","version":"1:1.1.1k-14.el8_6","language":"","licenses":["OpenSSL and ASL 2.0"],"metadata":{"epoch":1,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"openssl","version":"1.1.1k-14.el8_6"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"openssl","version":"1.1.1k-14.el8_6"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-75806","description":"A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-08","epss":0.00387,"percentile":0.30642}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"63061b05c6c4a08a","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libxml2:2.9.7-19.el8_10:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:rpm/redhat/libxml2@2.9.7-19.el8_10?arch=x86_64&distro=rhel-8.10&upstream=libxml2-2.9.7-19.el8_10.src.rpm","type":"rpm","version":"2.9.7-19.el8_10","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0:2.9.7-20.el8_10"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-32414","versionConstraint":"< 0:2.9.7-20.el8_10 (rpm)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"libxml2","version":"0:2.9.7-19.el8_10"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2025-32414","fix":{"state":"fixed","versions":["0:2.9.7-20.el8_10"],"available":[{"date":"2025-06-13","kind":"first-observed","version":"0:2.9.7-20.el8_10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32414","cwe":"CWE-393","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-32414","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-32414","date":"2026-10-08","epss":0.0037,"percentile":0.28845}],"risk":0.1961,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[{"id":"RHSA-2025:8958","link":"https://access.redhat.com/errata/RHSA-2025:8958"}],"dataSource":"https://access.redhat.com/security/cve/CVE-2025-32414","description":"A flaw was found in libxml2. This vulnerability allows out-of-bounds memory access due to incorrect handling of return values in xmlPythonFileRead and xmlPythonFileReadRaw. This is caused by a mismatch between the length of the file in bytes vs the length in characters, as unicode characters can occupy up to 4 bytes per character."},"relatedVulnerabilities":[{"id":"CVE-2025-32414","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-32414","cwe":"CWE-393","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-32414","cwe":"CWE-252","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-32414","date":"2026-10-08","epss":0.0037,"percentile":0.28845}],"urls":["https://gitlab.gnome.org/GNOME/libxml2/-/issues/889","https://lists.debian.org/debian-lts-announce/2025/04/msg00041.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-32414","description":"In libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters."}]},{"artifact":{"id":"d37d6b7d417f1820","cpes":["cpe:2.3:a:redhat:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:curl:curl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:rpm/redhat/curl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"0:7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.19563999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18924","description":"A flaw was found in libcurl. When libcurl handles HTTP/2 Server Push streams and the parent handle shares connections, a use-after-free vulnerability can occur during the cleanup process. This could lead to application crashes, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"4bb0692ec342f98b","cpes":["cpe:2.3:a:libcurl:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:libcurl:7.61.1-34.el8_10.3:*:*:*:*:*:*:*"],"name":"libcurl","purl":"pkg:rpm/redhat/libcurl@7.61.1-34.el8_10.3?arch=x86_64&distro=rhel-8.10&upstream=curl-7.61.1-34.el8_10.3.src.rpm","type":"rpm","version":"7.61.1-34.el8_10.3","language":"","licenses":["MIT"],"metadata":{"epoch":null,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl","version":"7.61.1-34.el8_10.3"}],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"curl","version":"7.61.1-34.el8_10.3"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.19563999999999995,"urls":[],"severity":"Low","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-18924","description":"A flaw was found in libcurl. When libcurl handles HTTP/2 Server Push streams and the parent handle shares connections, a use-after-free vulnerability can occur during the cleanup process. This could lead to application crashes, resulting in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"1435e8d59fac6b89","cpes":["cpe:2.3:a:redhat:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*","cpe:2.3:a:tar:tar:2\\:1.30-9.el8:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:rpm/redhat/tar@1.30-9.el8?arch=x86_64&distro=rhel-8.10&epoch=2&upstream=tar-1.30-9.el8.src.rpm","type":"rpm","version":"2:1.30-9.el8","language":"","licenses":["GPLv3+"],"metadata":{"epoch":2,"architecture":"x86_64","modularityLabel":""},"locations":[{"path":"/var/lib/rpm/Packages","layerID":"sha256:26017319066eb9ddbbc5d087f4c3554431206ba3d2bcccebc782db335c60106c","accessPath":"/var/lib/rpm/Packages","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"RpmMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-33056","versionConstraint":"none (unknown)"},"matcher":"rpm-matcher","searchedBy":{"distro":{"type":"redhat","version":"8.10"},"package":{"name":"tar","version":"2:1.30-9.el8"},"namespace":"redhat:distro:redhat:8"}}],"vulnerability":{"id":"CVE-2026-33056","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33056","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33056","date":"2026-10-08","epss":0.00415,"percentile":0.3379}],"risk":0.19505000000000003,"urls":[],"severity":"Medium","namespace":"redhat:distro:redhat:8","advisories":[],"dataSource":"https://access.redhat.com/security/cve/CVE-2026-33056","description":"A flaw was found in tar-rs, a Rust library for reading and writing tar archives. When unpacking a crafted tar archive, an attacker can exploit a symbolic link vulnerability. By including a symlink followed by a directory with the same name, the library incorrectly applies file permissions to the symlink's target. This allows an attacker to modify the permissions of arbitrary directories outside the intended extraction location."},"relatedVulnerabilities":[{"id":"CVE-2026-33056","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33056","cwe":"CWE-61","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33056","date":"2026-10-08","epss":0.00415,"percentile":0.3379}],"urls":["https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446","https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33056","description":"tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, the tar crate's unpack_dir function uses fs::metadata() to check whether a path that already exists is a directory. Because fs::metadata() follows symbolic links, a crafted tarball containing a symlink entry followed by a directory entry with the same name causes the crate to treat the symlink target as a valid existing directory — and subsequently apply chmod to it. This allows an attacker to modify the permissions of arbitrary directories outside the extraction root. This issue has been fixed in version 0.4.45."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T19:36:54.510Z","grype_db_version":"2026-10-09T06:32:32.000Z"}